CVE-2005-2773criticalunder attackCWE-77

CVE-2005-2773

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 75%
from disclosure to weapon0 days
Published on NVDSep 2
1st PoCAug 30
metasploitAug 25
CISA KEV+6048d
exploitation probability
75%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

HP OpenView Network Node Manager has a critical flaw that allows attackers to run malicious commands on the server by sending specially crafted requests. This happens because the software doesn't properly filter dangerous characters in user input.

Technical detail

CWE-77 command injection vulnerability in OpenView Network Node Manager 6.2-7.50 affects multiple OVPl scripts (connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, ecscmg.ovpl) through unvalidated node parameters. Remote attackers can inject shell metacharacters to execute arbitrary system commands without authentication, achieving full server compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.