« Volver al listado

CVE-2012-3253

Estado: ModificadaAlta (10)—

Multiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by an integer overflow and heap-based buffer overflow in img.exe for a crafted message packet.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-3253",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-30T17:55:01.497",
  "references": [
    {
      "url": "http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03473459",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://zerodayinitiative.com/advisories/ZDI-12-164/",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c03473459",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://zerodayinitiative.com/advisories/ZDI-12-164/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code via crafted input, as demonstrated by an integer overflow and heap-based buffer overflow in img.exe for a crafted message packet."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades en HP Intelligent Management Center (IMC) anterior a v5.0 E0101P05 permite a atacantes remotos ejecutar código arbitrario a través de una entrada manipulada, como se muestra a través de un desbordamiento de entero y un desbordamiento de búfer basado en memoria dinámica en img.exe para un paquete de mensaje manipulado."
    }
  ],
  "lastModified": "2026-06-16T23:42:51.603",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:*:e0101h04:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7ED29760-E1A4-4324-A086-59F2FE7C9E8F",
              "versionEndIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A78300D-0507-4826-9BFE-0CF3C470626E"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E3BD46C-CD5A-4DD3-A0B2-1B445F719698"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101h03:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02081D9F-44B2-4F39-B1EB-0282701FDD4A"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101l01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D97F1E65-6A0C-491E-8EBC-643F38F1B0C6"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101l02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1C229E5-9778-4D00-A9F3-877E30013BD5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}