peter bassill · operator
$ cve CVE-2005-2773 JSON

CVE-2005-2773 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 74.6% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS74.59% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2005-09-02
Last modified2026-06-16

CISA KEV

NameHP OpenView Network Node Manager Remote Code Execution Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productHewlett Packard (HP) / OpenView Network Node Manager
Ransomware usenone reported

Affected (1)

VendorProduct
hpopenview network node manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD