CVE-2016-2004 is a critical authentication bypass vulnerability affecting HPE Data Protector versions before 7.03_108, 8.x before 8.15, and 9.x before 9.06, allowing remote attackers to execute arbitrary code. This vulnerability, a CVSS 9.8 Critical, has a low attack complexity and requires no user interaction, enabling full compromise of confidentiality, integrity, and availability. Public exploit code is readily available, including Metasploit modules and ExploitDB entries, and it has garnered significant community discussion and media coverage, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0, < 7.03_108CPE matchmatch criteria | cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.15CPE matchmatch criteria | cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.06CPE matchmatch criteria | cpe:2.3:a:hp:data_protector:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.