CVE-2014-5160
mediumCVSS v3 Base Score
6.4
AV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS Score
30.0%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
P
Availability
P
Vulnerability Report
Generated by CyberWatcher
Description
Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or delete arbitrary files via an opcode-305 request. NOTE: the vendor reportedly asserts that this behavior is "by design.
CWE
CWE-22Affected Products
hp data protector