CVE-2012-3253
Multiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by an integer overflow and heap-based buffer overflow in img.exe for a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by an integer overflow and heap-based buffer overflow in img.exe for a crafted message packet.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 9.59% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- hp/intelligent management center
- Source
- hp-security-alert@hp.com
References
- http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03473459Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-12-164/
- http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03473459Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-12-164/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.