// For flags

CVE-2011-1867

HP iNode Management Center iNodeMngChecker.exe Remote Code Execution Vulnerability

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Stack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 before SP1 E0101P03 components in HP Intelligent Management Center (aka iNode Management Center) allows remote attackers to execute arbitrary code via a 0x0A0BF007 packet.

Desbordamiento de búfer basado en pila en iNodeMngChecker.exe en el User Access Manager (UAM ) v5.0 antes de SP1 E0101P03 y Endpoint Admission Defense(EAD )v5.0 antes de SP1 E0101P03,componentes de HP Intelligent Management Center (también conocido como iNode Management Center), permite a atacantes remotos ejecutar código de su elección a través de un paquete 0x0A0BF007.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP H3C/3Com iNode Management Center. Authentication is not required to exploit this vulnerability.
The flaw exists within the iNOdeMngChecker.exe component which listens by default on TCP port 9090. When handling the 0x0A0BF007 packet type the process blindly copies user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the SYSTEM user.

*Credits: Luigi Auriemma
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-05-03 CVE Reserved
  • 2011-07-01 CVE Published
  • 2024-02-29 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hp
Search vendor "Hp"
Endpoint Admission Defense
Search vendor "Hp" for product "Endpoint Admission Defense"
5.0
Search vendor "Hp" for product "Endpoint Admission Defense" and version "5.0"
-
Affected
Hp
Search vendor "Hp"
Endpoint Admission Defense
Search vendor "Hp" for product "Endpoint Admission Defense"
5.0
Search vendor "Hp" for product "Endpoint Admission Defense" and version "5.0"
e0101
Affected
Hp
Search vendor "Hp"
Intelligent Management Center
Search vendor "Hp" for product "Intelligent Management Center"
*-
Affected
Hp
Search vendor "Hp"
User Access Manager
Search vendor "Hp" for product "User Access Manager"
5.0
Search vendor "Hp" for product "User Access Manager" and version "5.0"
-
Affected
Hp
Search vendor "Hp"
User Access Manager
Search vendor "Hp" for product "User Access Manager"
5.0
Search vendor "Hp" for product "User Access Manager" and version "5.0"
e0101
Affected