CVE-2005-2773 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 74.6% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 74.59% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2005-09-02 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | HP OpenView Network Node Manager Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | Hewlett Packard (HP) / OpenView Network Node Manager |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| hp | openview network node manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP OpenView Network Node Manager (OV NNM) - 'connectedNodes.ovp'l Remote Command Execution (Metasploit) | 2010-07-03 |
| exploit-db | HP OpenView Network Node Manager 7.50 - Remote Command Execution | 2005-08-30 |
References
- http://marc.info/?l=bugtraq&m=112499121725662&w=2
- http://secunia.com/advisories/16555/
- http://www.securityfocus.com/advisories/9150
- http://www.securityfocus.com/bid/14662
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21999
- http://marc.info/?l=bugtraq&m=112499121725662&w=2
- http://secunia.com/advisories/16555/
- http://www.securityfocus.com/advisories/9150
- http://www.securityfocus.com/bid/14662
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21999
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773
→ the Explorer · watch your stack · NVD