{
    "id": "CVE-2011-4162",
    "published": "2011-12-05 11:55:07",
    "last_modified": "2026-06-16 23:34:31",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-119",
    "description": "The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.",
    "epss_score": "0.07648",
    "epss_percentile": "0.94404",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-03 18:17:10",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "hp",
            "product": "protecttools_device_access_manager"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "36403",
            "title": "HP Device Access Manager for HP ProtectTools 5.0/6.0 - Heap Memory Corruption",
            "date": "2011-12-02",
            "url": "https://www.exploit-db.com/exploits/36403"
        }
    ],
    "refs_list": [
        "http://marc.info/?l=bugtraq&m=132284686204608&w=2",
        "http://marc.info/?l=bugtraq&m=134152032516062&w=2",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/71600",
        "https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.html",
        "http://marc.info/?l=bugtraq&m=132284686204608&w=2",
        "http://marc.info/?l=bugtraq&m=134152032516062&w=2",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/71600",
        "https://www.htbridge.ch/advisory/heap_memory_corruption_in_hp_device_access_manager_for_protect_tools_information_store.html"
    ]
}