Executive brief
HP OpenView Network Node Manager (NNM) contains a command injection vulnerability due to improper neutralization of shell metacharacters in multiple scripts, including connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. A remote, unauthenticated attacker can exploit this by providing malicious input to parameters such as 'node', leading to arbitrary command execution on the host system.
Affected products
- HP OpenView Network Node Manager 6.2 through 7.50
Timeline
- 2005-08-25: disclosed: Initial public disclosure via Bugtraq and other sources.
- 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.