peter bassill · operator
$ cve CVE-2011-4162 JSON

CVE-2011-4162 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.65% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2011-12-05
Last modified2026-06-16

Affected (1)

VendorProduct
hpprotecttools device access manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD