CVE-2011-4162
Summary
| CVE | CVE-2011-4162 |
|---|---|
| State | PUBLISHED |
| Assigner | hp |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-05 11:55:07 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hp | Protecttools Device Access Manager | 6.0.0.10 | All | All | All |
| Application | Hp | Protecttools Device Access Manager | 6.0.0.9 | All | All | All |
| Application | Hp | Protecttools Device Access Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| '[security bulletin] HPSBHF02723 SSRT100536 rev.1 - HP Protect Tools Device Access Manager for Window' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Vendor Advisory |
| '[security bulletin] HPSBGN02750 SSRT100795 rev.1 - HP ProtectTools Enterprise Device Access Manager' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| High-Tech Bridge SA - Heap Memory Corruption in HP Device Access Manager for Protect Tools Information Store | af854a3a-2127-422b-91ae-364da2661108 | www.htbridge.ch | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.