← Vulnerability feed

Vulnerability record · CVE-2012-3274 · published 6 December 2012

CVE-2012-3274: HP Intelligent Management Center UAM stack buffer overflow via log data

Hp · Intelligent Management Center

HP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, triggered through vectors related to log data. A remote, unauthenticated attacker can overflow the buffer and execute arbitrary code, making this a full-compromise flaw in an enterprise management platform.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus very high EPSS, warrants critical handling despite no confirmed in-the-wild exploitation.

What it is

HP Intelligent Management Center (IMC) before 5.1 E0101P01 contains a stack-based buffer overflow in uam.exe in the User Access Manager component, triggered through vectors related to log data. A remote, unauthenticated attacker can overflow the buffer and execute arbitrary code, making this a full-compromise flaw in an enterprise management platform.

Impact

An attacker gains remote code execution on the IMC server, which can lead to full control of the host and the managed network infrastructure it administers.

Attack surface

The vulnerability is network-reachable (AV:N) with low complexity and no authentication required (Au:N), so it can be triggered by sending crafted log-related data to the UAM component. No user interaction is indicated by the vector.

Exploitation

Not listed in CISA KEV and no reference tags indicate a public exploit, but EPSS is 0.61762 (99.1st percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Apply the HP fix by upgrading IMC to 5.1 E0101P01 or later; this is the only definitive remediation.
  • If patching is delayed, restrict network access to the UAM component and IMC management interfaces to trusted administrative networks only.
  • Segment the IMC server from general user and internet-facing networks to limit reachability of the vulnerable service.
  • Monitor HP advisories and the ZDI advisory for updated guidance or workarounds.
  • Treat the IMC host as high-value and enforce least privilege on any accounts or services that can reach it.

Detection

  • Monitor for crashes or abnormal termination of uam.exe on IMC hosts, which may indicate overflow attempts.
  • Inspect network traffic to the UAM service for oversized or malformed log-data payloads.
  • Alert on unexpected child processes or command execution spawned by uam.exe.
  • Review IMC host logs for anomalous access to the UAM component from untrusted source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3274 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-4822HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and its Branch Intelligent Management System (BIMS) module contain an unspecified vulnerability that lets remo…EPSS 63%analysed10.0CVE-2012-5201HP Intelligent Management Center remote code execution flawHP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 E0401 contain an unspecified …EPSS 64%analysed10.0CVE-2012-5209Hp intelligent management center vulnerabilityUnspecified vulnerability in HP Intelligent Management Center (iMC) and Intelligent Management Center for Automated Network Manager (ANM) before 5.2 …EPSS 8.6%10.0CVE-2012-3253Hp intelligent management center vulnerabilityMultiple unspecified vulnerabilities in HP Intelligent Management Center (IMC) before 5.0 E0101P05 allow remote attackers to execute arbitrary code v…EPSS 9.6%10.0CVE-2011-1867Hp endpoint admission defense memory buffer overflow vulnerabilityStack-based buffer overflow in iNodeMngChecker.exe in the User Access Manager (UAM) 5.0 before SP1 E0101P03 and Endpoint Admission Defense (EAD) 5.0 …EPSS 26%10.0CVE-2011-2331Hp intelligent management center vulnerabilityInteger overflow in img.exe in HP Intelligent Management Center (IMC) allows remote attackers to execute arbitrary code via a crafted length value in…EPSS 13%10.0CVE-2011-1852Hp intelligent management center memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execu…EPSS 15%10.0CVE-2011-1853Hp intelligent management center improper input validation vulnerabilitytftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a (1) large or (2)…EPSS 11%

Source: NIST National Vulnerability Database (record CVE-2012-3274), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.