Vulnerability record · CVE-2009-3999 · published 20 January 2010
CVE-2009-3999: HP Power Manager formExportDataLogs stack buffer overflow
Hp · Power Manager
HP Power Manager before 4.2.10 contains a stack-based buffer overflow in the goform/formExportDataLogs handler, triggered by an overly long fileName parameter. Because the flaw is remotely reachable without authentication and can corrupt the stack, it is a serious pre-auth code execution risk for exposed installations.
Description
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote stack overflow with a CVSS 2.0 base score of 10 and very high EPSS probability makes this a top remediation priority for any exposed HP Power Manager instance.
What it is
HP Power Manager before 4.2.10 contains a stack-based buffer overflow in the goform/formExportDataLogs handler, triggered by an overly long fileName parameter. Because the flaw is remotely reachable without authentication and can corrupt the stack, it is a serious pre-auth code execution risk for exposed installations.
Impact
A remote attacker can overwrite stack memory and execute arbitrary code in the context of the affected service, potentially gaining full control of the host.
Attack surface
The flaw is reached over the network through the goform/formExportDataLogs endpoint with a crafted fileName parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
The record is not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high at roughly 0.718 (99.4th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade HP Power Manager to version 4.2.10 or later, which the advisory states fixes the issue.
- If immediate upgrade is not possible, restrict network access to the Power Manager management interface to trusted hosts only.
- Place the service behind a firewall or reverse proxy and block untrusted access to the goform/formExportDataLogs endpoint.
- Monitor vendor advisories for any updated guidance or replacement builds for end-of-life versions.
Detection
- Inspect web server or application logs for requests to goform/formExportDataLogs with unusually long or malformed fileName parameters.
- Alert on crashes or restarts of the Power Manager service that coincide with such requests.
- Hunt for unexpected child processes or command execution spawned by the Power Manager service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-3999 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.