HP Data Protector Express Unspecified Remote Code Execution

  Severity: CRITICAL
  CVE Identifier: CVE-2012-0121
  Advisory Date: JUL 21, 2015

  DESCRIPTION

Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1392.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1005095
  Trend Micro Deep Security DPI Rule Name: 1005095 - HP Data Protector Create New Folder Buffer Overflow Vulnerability

  AFFECTED SOFTWARE AND VERSION

  • hp data_protector_express 5.0
  • hp data_protector_express 6.0