Lucene search

K
cveHpCVE-2010-2703
HistoryJul 28, 2010 - 12:48 p.m.

CVE-2010-2703

2010-07-2812:48:53
CWE-119
hp
web.nvd.nist.gov
42
cve-2010-2703
buffer overflow
hp openview
nnm
remote code execution
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.961

Percentile

99.5%

Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

Affected configurations

Nvd
Node
hpopenview_network_node_managerMatch7.51-windows
OR
hpopenview_network_node_managerMatch7.53-windows
AND
microsoftwindows
VendorProductVersionCPE
hpopenview_network_node_manager7.51cpe:2.3:a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
hpopenview_network_node_manager7.53cpe:2.3:a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

Low

EPSS

0.961

Percentile

99.5%