APP: HP OpenView Network Node Manager webappmon.exe execvp_nc Buffer Overflow

This signature detects attempts to exploit a known vulnerability in HP OpenView Network Node Manager (NNM) ov.dll, which is invoked by the CGI program webappmon.exe. It is due to a boundary error when processing maliciously crafted HTTP requests. A remote unauthenticated attacker can exploit this by sending a crafted HTTP request to a target server, potentially causing arbitrary code to be injected and executed.

Extended Description

HP OpenView Network Node Manager (OV NNM) is prone to a remote code-execution vulnerability. An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. The issue affects HP OpenView Network Node Manager versions 7.51 and 7.53 running on the Windows platform.

Affected Products

Hp openview_network_node_manager

Short Name
APP:HPOV:NNM-EXECVP-NC-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Buffer CVE-2010-1551 CVE-2010-2703 HP Manager Network Node OpenView Overflow bid:40067 bid:41829 execvp_nc webappmon.exe
Release Date
09/29/2010
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Hp

CVSS Score

10.0

Found a potential security threat?