Stack-based buffer overflow in HP Power Manager
CVE-2009-3999
Currently unrated
Key Information:
- Vendor
HP
- Status
- Vendor
- CVE Published:
- 20 January 2010
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 71%
What is CVE-2009-3999?
A stack-based buffer overflow exists in the goform/formExportDataLogs function within HP Power Manager, prior to version 4.2.10. This flaw enables remote attackers to execute arbitrary code by exploiting the vulnerability through a specially crafted long 'fileName' parameter. The issue poses a significant risk, allowing unauthorized manipulation of the system.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.