CVE-2011-1220 describes a stack-based buffer overflow in the lcfd.exe component of IBM Tivoli Management Framework versions 3.7.1, 4.1, 4.1.1, and 4.3.1. This critical vulnerability, with a CVSS score of 9.0, allows remote authenticated attackers to execute arbitrary code by supplying an overly long 'opts' field. While not currently listed in CISA's KEV catalog, exploit code is publicly available via Metasploit, indicating a high potential for exploitation despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.1CPE matchmatch criteria | cpe:2.3:a:ibm:tivoli_management_framework:3.7.1:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:ibm:tivoli_management_framework:4.1:*:*:*:*:*:*:* | ||
4.1.1CPE matchmatch criteria | cpe:2.3:a:ibm:tivoli_management_framework:4.1.1:*:*:*:*:*:*:* | ||
4.3.1CPE matchmatch criteria | cpe:2.3:a:ibm:tivoli_management_framework:4.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] IBM Tivoli Management Framework Endpoint lcfd.exe opts Field Handling Remote Buffer Overflow
May 31, 2011[R1] IBM Tivoli Management Framework Endpoint lcfd.exe opts Field Handling Remote Buffer Overflow
May 31, 2011[R1] IBM Tivoli Management Framework Endpoint lcfd.exe opts Field Handling Remote Buffer Overflow
May 31, 2011[R1] IBM Tivoli Management Framework Endpoint lcfd.exe opts Field Handling Remote Buffer Overflow
May 31, 2011