CVE-2014-5160 describes multiple directory traversal vulnerabilities within the crs.exe component of HP Data Protector. These flaws allow unauthenticated remote attackers to create arbitrary files via an opcode-1091 request, or create and delete arbitrary files through an opcode-305 request. With a CVSS score of 6.4, this vulnerability presents a moderate risk, requiring no authentication and having low attack complexity, potentially leading to partial integrity and availability impacts. Despite its FAUCET Risk Score of 90/100 and an EPSS score indicating higher exploitability than many CVEs, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.10CPE matchmatch criteria | cpe:2.3:a:hp:data_protector:6.10:*:*:*:*:*:*:* | ||
6.11CPE matchmatch criteria | cpe:2.3:a:hp:data_protector:6.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.