Short Name |
APP:HPOV:SDP-OF |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
HP OpenView Storage Data Protector Stack Buffer Overflow |
Release Date |
2010/10/01 |
Update Number |
1784 |
Supported Platforms |
idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known buffer overflow vulnerability in HP OpenView Storage Data Protector. It is due to a boundary error when processing requests sent to the Cell Request Service (crs.exe) process. A remote unauthenticated attacker can exploit this by sending a crafted request with opcode 0x010b to a target server, potentially causing arbitrary code to be injected and executed in the security context of the user configured during the service installation (Administrator by default).