{"api_version":"1","generated_at":"2026-07-24T20:33:25+00:00","cve":"CVE-2009-2680","urls":{"html":"https://cve.report/CVE-2009-2680","api":"https://cve.report/api/cve/CVE-2009-2680.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2680","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2680"},"summary":{"title":"CVE-2009-2680","description":"Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-24 16:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53237","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53237","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36764","name":"http://secunia.com/advisories/36764","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP StorageWorks Products Remote Management Interface Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"HPSBST02459 SSRT080134 rev.2 - HP StorageWorks Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders, Denial of Service (DoS) - c01868405 - \r\n\t\tHP Business Support Center","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/2662","name":"http://www.vupen.com/english/advisories/2009/2662","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36388","name":"http://www.securityfocus.com/bid/36388","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP StorageWorks Products Remote Management Interface Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/58131","name":"http://www.osvdb.org/58131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1022905","name":"http://securitytracker.com/id?1022905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - HP StorageWorks Remote Management Interface Lets Remote Users Deny Service","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2680","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2680","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2680","vulnerable":"1","versionEndIncluding":"2.30","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"hp","cpe5":"storageworks_1\\/8_g2_tape_autoloader","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2680","vulnerable":"1","versionEndIncluding":"4.20","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"hp","cpe5":"storageworks_msl2024_tape_library","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2680","vulnerable":"1","versionEndIncluding":"6.50","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"hp","cpe5":"storageworks_msl4048_tape_library","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2680","vulnerable":"1","versionEndIncluding":"8.90","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"hp","cpe5":"storageworks_msl8096_tape_library","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:59:56.877Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2009-2662","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/2662"},{"name":"36388","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36388"},{"name":"58131","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/58131"},{"name":"1022905","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1022905"},{"name":"36764","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36764"},{"name":"storageworks-rmi-dos(53237)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53237"},{"name":"SSRT080134","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"},{"name":"HPSBST02459","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2009-2662","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/2662"},{"name":"36388","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36388"},{"name":"58131","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/58131"},{"name":"1022905","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1022905"},{"name":"36764","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36764"},{"name":"storageworks-rmi-dos(53237)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53237"},{"name":"SSRT080134","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"},{"name":"HPSBST02459","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2680","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2009-2662","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/2662"},{"name":"36388","refsource":"BID","url":"http://www.securityfocus.com/bid/36388"},{"name":"58131","refsource":"OSVDB","url":"http://www.osvdb.org/58131"},{"name":"1022905","refsource":"SECTRACK","url":"http://securitytracker.com/id?1022905"},{"name":"36764","refsource":"SECUNIA","url":"http://secunia.com/advisories/36764"},{"name":"storageworks-rmi-dos(53237)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53237"},{"name":"SSRT080134","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"},{"name":"HPSBST02459","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01868405"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2680","datePublished":"2009-09-24T16:00:00.000Z","dateReserved":"2009-08-05T00:00:00.000Z","dateUpdated":"2024-08-07T05:59:56.877Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-24 16:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":7.8,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:hp:storageworks_1\\/8_g2_tape_autoloader:*:*:*:*:*:*:*:*","versionEndIncluding":"2.30","matchCriteriaId":"72CAE62D-B7B1-4DC7-AD10-18B27E68BF9C"},{"vulnerable":true,"criteria":"cpe:2.3:h:hp:storageworks_msl2024_tape_library:*:*:*:*:*:*:*:*","versionEndIncluding":"4.20","matchCriteriaId":"5BC0783B-0D2A-4BEA-8AC2-D0E23A84A961"},{"vulnerable":true,"criteria":"cpe:2.3:h:hp:storageworks_msl4048_tape_library:*:*:*:*:*:*:*:*","versionEndIncluding":"6.50","matchCriteriaId":"B13322F0-91CD-4CC3-A1A7-95E8313679A9"},{"vulnerable":true,"criteria":"cpe:2.3:h:hp:storageworks_msl8096_tape_library:*:*:*:*:*:*:*:*","versionEndIncluding":"8.90","matchCriteriaId":"5C06FCD7-20FE-423E-83AD-2F36FF1BEEF2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2680","Ordinal":"1","Title":"CVE-2009-2680","CVE":"CVE-2009-2680","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2680","Ordinal":"1","NoteData":"Unspecified vulnerability in the Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders in HP StorageWorks 1/8 G2 Tape Autoloader firmware 2.30 and earlier, MSL2024 Tape Library firmware 4.20 and earlier, MSL4048 Tape Library firmware 6.50 and earlier, and MSL8096 Tape Library firmware 8.90 and earlier allows remote attackers to cause a denial of service via unknown vectors.","Type":"Description","Title":"CVE-2009-2680"},{"CveYear":"2009","CveId":"2680","Ordinal":"2","NoteData":"2009-09-24","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2680","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}