CVE-2005-2773
CRITICAL(9.8)KEVLikely Exploited
HP OpenView Network Node Manager Remote Code Execution Vulnerability
Description
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| hp | openview network node manager | >= 6.2, <= 7.50 |
Multiple CVSS Assessments
Source: [email protected](Primary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- http://marc.info/?l=bugtraq&m=112499121725662&w=2(Exploit, Issue Tracking, Mailing List)
- http://secunia.com/advisories/16555/(Not Applicable)
- http://www.securityfocus.com/advisories/9150(Broken Link)
- http://www.securityfocus.com/bid/14662(Broken Link)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21999(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.