Lucene search

K
cveMitreCVE-2008-1697
HistoryApr 08, 2008 - 5:05 p.m.

CVE-2008-1697

2008-04-0817:05:00
CWE-119
mitre
web.nvd.nist.gov
31
cve
2008
1697
buffer overflow
hp
openview
nnm
remote code execution
http
ovas.exe

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.95

Percentile

99.4%

Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain topology/homeBaseView request. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
hpopenview_network_node_managerRangeโ‰ค7.53
OR
hpopenview_network_node_managerMatch7.0.1
OR
hpopenview_network_node_managerMatch7.51
VendorProductVersionCPE
hpopenview_network_node_manager*cpe:2.3:a:hp:openview_network_node_manager:*:*:*:*:*:*:*:*
hpopenview_network_node_manager7.0.1cpe:2.3:a:hp:openview_network_node_manager:7.0.1:*:*:*:*:*:*:*
hpopenview_network_node_manager7.51cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.95

Percentile

99.4%