CVE-2011-4162
The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.65% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- hp/protecttools device access manager
- Source
- hp-security-alert@hp.com
References
- http://marc.info/?l=bugtraq&m=132284686204608&w=2Vendor Advisory
- http://marc.info/?l=bugtraq&m=134152032516062&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71600
- https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.htmlExploit
- http://marc.info/?l=bugtraq&m=132284686204608&w=2Vendor Advisory
- http://marc.info/?l=bugtraq&m=134152032516062&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71600
- https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.htmlExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.