CVE-2005-2773
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
HP OpenView Network Node Manager has a critical flaw that allows attackers to run malicious commands on the server by sending specially crafted requests. This happens because the software doesn't properly filter dangerous characters in user input.
CWE-77 command injection vulnerability in OpenView Network Node Manager 6.2-7.50 affects multiple OVPl scripts (connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, ecscmg.ovpl) through unvalidated node parameters. Remote attackers can inject shell metacharacters to execute arbitrary system commands without authentication, achieving full server compromise.
The full analysis of this CVE is available in Portuguese →