CVE-2013-2342

high
Published 2013-06-30 · Modified 2026-04-29
CVSS v3
CVSS v2
7.7
VIR risk
7.7

Description

The HP StoreOnce D2D backup system with software before 3.0.0 has a default password of badg3r5 for the HPSupport account, which allows remote attackers to obtain administrative access and delete data via an SSH session.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: hp-security-alert@hp.com — https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03813919

Application impact

VendorProductVersionsFixed
hp hpstoreonce_d2d{"endIncluding":"2.2.17"}
hp hpstoreonce_d2d2.1.01
hp hpstoreonce_d2d2.2.00
hp hpstoreonce_d2d2.2.10
hp hpstoreonce_d2d2.2.13
hp hpstoreonce_d2d2.2.14
hp hpstoreonce_d2d2.2.16

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.