Vulnerability Name: | CVE-2011-1867 (CCN-68348) | ||||||||
Assigned: | 2011-06-30 | ||||||||
Published: | 2011-06-30 | ||||||||
Updated: | 2018-10-09 | ||||||||
Summary: | Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via a 0x0A0BF007 packet. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
7.4 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-1867 Source: CCN Type: HPSB3C02687 SSRT100377 HP Intelligent Management Center User Access Manager (UAM) and Endpoint Admission Defense (EAD), Remote Execution of Arbitrary Code Source: HP Type: Vendor Advisory SSRT100377 Source: CCN Type: SA45129 HP Intelligent Management Center Products Unspecified Code Execution Vulnerability Source: SECUNIA Type: Vendor Advisory 45129 Source: SREASON Type: UNKNOWN 8302 Source: SECTRACK Type: UNKNOWN 1025740 Source: OSVDB Type: UNKNOWN 73597 Source: CCN Type: OSVDB ID: 73597 HP Intelligent Management Center Products iNOdeMngChecker.exe Packet Parsing Overflow Source: BUGTRAQ Type: UNKNOWN 20110701 ZDI-11-232: HP iNode Management Center iNodeMngChecker.exe Remote Code Execution Vulnerability Source: BID Type: UNKNOWN 48527 Source: CCN Type: BID-48527 HP Intelligent Management Centre Products 'iNodeMngChecker.exe' Remote Code Execution Vulnerability Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-11-232/ Source: XF Type: UNKNOWN hp-imc-unspec-code-execution(68348) Source: XF Type: UNKNOWN hp-imc-unspec-code-execution(68348) Source: CCN Type: ZDI-11-232 HP iNode Management Center iNodeMngChecker.exe Remote Code Execution Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |