Remote Code Execution and Denial of Service Vulnerability in HP Protect Tools Device Access Manager

Remote Code Execution and Denial of Service Vulnerability in HP Protect Tools Device Access Manager

CVE-2011-4162 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The (1) AddUser, (2) AddUserEx, (3) RemoveUser, (4) RemoveUserByGuide, (5) RemoveUserEx, and (6) RemoveUserRegardless methods in HP Protect Tools Device Access Manager (PTDAM) before 6.1.0.1 allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a long SidString argument.

Learn more about our User Device Pen Test.