Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100346
Category:Web application abuses
Title:HP Power Manager Management Web Server Login RCE Vulnerability
Summary:HP Power Manager is prone to a remote code execution (RCE) vulnerability because it; fails to properly bounds-check user-supplied data.
Description:Summary:
HP Power Manager is prone to a remote code execution (RCE) vulnerability because it
fails to properly bounds-check user-supplied data.

Vulnerability Impact:
An attacker can exploit this issue to execute arbitrary code with SYSTEM
credentials, resulting in a complete compromise of the affected computer. Failed exploit attempts will result in a
denial-of-service condition.

Solution:
The vendor has released updates and an advisory. Please see the references
for details.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-2685
BugTraq ID: 36933
http://www.securityfocus.com/bid/36933
Bugtraq: 20091105 ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/507708/100/0/threaded
HPdes Security Advisory: HPSBMA02474
http://marc.info/?l=bugtraq&m=125744000032141&w=2
HPdes Security Advisory: SSRT090107
http://www.zerodayinitiative.com/advisories/ZDI-09-081/
http://www.osvdb.org/59684
http://securitytracker.com/id?1023140
http://secunia.com/advisories/37276
http://www.vupen.com/english/advisories/2009/3154
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.