Vulnerability Name: | CVE-2009-3840 (CCN-54314) | ||||||||
Assigned: | 2009-11-17 | ||||||||
Published: | 2009-11-17 | ||||||||
Updated: | 2009-11-24 | ||||||||
Summary: | The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3840 Source: CCN Type: HP Security Bulletin HPSBMA02477 SSRT090177 rev.2 HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS) Source: HP Type: Patch, Vendor Advisory SSRT090177 Source: OSVDB Type: UNKNOWN 60200 Source: FULLDISC Type: UNKNOWN 20091117 CORE-2009-0814: HP Openview NNM 7.53 Invalid DB Error Code vulnerability Source: CCN Type: SA37376 HP OpenView Network Node Manager Database Service Denial of Service Source: MISC Type: UNKNOWN http://www.coresecurity.com/content/openview_nnm_internaldb_dos Source: CCN Type: OSVDB ID: 60200 HP OpenView Network Node Manager Database Service (ovdbrun.exe) TCP Packet Handling Remote DoS Source: CCN Type: OSVDB ID: 60375 IBM solidDB Database Service (solid.exe) Malformed Error Code Remote DoS Source: BID Type: Exploit, Patch 37046 Source: CCN Type: BID-37046 HP OpenView Network Node Manager 'ovdbrun.exe' Denial of Service Vulnerability Source: XF Type: UNKNOWN openviewnnm-ovdbrun-dos(54314) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |