Junglewise Threat Intelligence

CVE-2005-2773: HP OpenView Network Node Manager Remote Code Execution Vulnerability

CVE-2005-2773 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Vendors: Hp, Hewlett Packard Enterprise.

Executive brief

HP OpenView Network Node Manager (NNM) contains a command injection vulnerability due to improper neutralization of shell metacharacters in multiple scripts, including connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. A remote, unauthenticated attacker can exploit this by providing malicious input to parameters such as 'node', leading to arbitrary command execution on the host system.

Affected products

  • HP OpenView Network Node Manager 6.2 through 7.50

Timeline

  • 2005-08-25: disclosed: Initial public disclosure via Bugtraq and other sources.
  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.