APP: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Buffer Overflow

This signature detects attempts to exploit a known buffer overflow vulerability in HP OpenView Network Node Manager (NNM) ovwebsnmpsrv.exe. It is due to a boundary error when handling HTTP requests sent to the jovgraph.exe CGI application. A remote unauthenticated attacker can exploit this by sending a crafted HTTP request to a target server, potentially causing arbitrary code to be injected and executed in the security context of the Internet Guest account.

Extended Description

HP OpenView Network Node Manager (NNM) is prone to a remote buffer-overflow vulnerability. An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.

Affected Products

Hp openview_network_node_manager

Short Name
APP:HPOV:OVWEBSNMPSRV-OF
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Argument Buffer CVE-2010-1960 CVE-2010-1961 CVE-2010-1964 Command HP Line NNM OpenView Overflow bid:40637 bid:40638 bid:40873 ovwebsnmpsrv.exe
Release Date
10/01/2010
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Hp

CVSS Score

7.5

10.0

Found a potential security threat?