« Back to list

CVE-2012-3274

Status: ModifiedHigh (10)—💥 Exploit

Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-3274",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "hp-security-alert@hp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-12-06T11:45:47.310",
  "references": [
    {
      "url": "http://zerodayinitiative.com/advisories/ZDI-12-171/",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03589863",
      "source": "hp-security-alert@hp.com"
    },
    {
      "url": "http://zerodayinitiative.com/advisories/ZDI-12-171/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03589863",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de desobrdamiento de búfer basado en pila en uam.exe en el componente User Access Manager (UAM) en HP Intelligent Management Center (IMC) antes de v5.1 E0101P01 permite a atacantes remotos ejecutar código de su elección a través de vectores relacionados con el registro de datos."
    }
  ],
  "lastModified": "2026-06-16T23:42:54.593",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB86100C-9CFB-4078-96A8-4019BE64C500",
              "versionEndIncluding": "5.1"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A78300D-0507-4826-9BFE-0CF3C470626E"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E3BD46C-CD5A-4DD3-A0B2-1B445F719698"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101h03:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02081D9F-44B2-4F39-B1EB-0282701FDD4A"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101h04:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "491C786C-A73F-4D5C-83E8-A471EA442A4B"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101l01:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D97F1E65-6A0C-491E-8EBC-643F38F1B0C6"
            },
            {
              "criteria": "cpe:2.3:a:hp:intelligent_management_center:5.0:e0101l02:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1C229E5-9778-4D00-A9F3-877E30013BD5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "hp-security-alert@hp.com"
}