HP Intelligent Management Center tftpserver.exe Remote Code Execution (CVE-2011-1851)
| Check Point Reference: | CPAI-2011-546 | |
| Date Published: | ||
| Severity: | ||
| Source: | SecurityFocus Advisory 47789 | |
| Industry Reference(s): | CVE-2011-1851 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? HP Intelligent Management Center prior to 5.0 (E0101L01) | ||
| Vulnerability Description A remote code execution vulnerability has been reported in HP Intelligent Management Center. |
||
|
Vulnerability Details The vulnerability is due to improper verification of the destination buffer's size while handling the transfer mode field within the tftpserver.exe component. A remote attacker could exploit this vulnerability by sending a malformed TFTP packet to an affected server. Successful exploitation could lead to arbitrary code execution within the security context of the running service. |
Protection Overview
This protection will detect and block the transferring of malicious TFTP packets.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.