Vulnerability Name:
CVE-2010-1964 (CCN-59625)
Assigned:
2010-06-08
Published:
2010-06-08
Updated:
2018-10-10
Summary:
Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.
CVSS v3 Severity:
10.0 Critical
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Changed
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
7.5 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
)
5.9 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
9.3 High
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
7.3 High
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-noinfo
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2010-1964
Source: CCN
Type: HP Security Bulletin HPSBMA02537 SSRT010027
OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code
Source: OSVDB
Type: UNKNOWN
65552
Source: HP
Type: Patch
SSRT010027
Source: SREASON
Type: UNKNOWN
8155
Source: CCN
Type: OSVDB ID: 65552
HP OpenView Network Node Manager (OV NNM) ovwebsnmpsrv.exe jovgraph.exe CGI main() Function Remote Code Execution
Source: BUGTRAQ
Type: UNKNOWN
20100616 ZDI-10-108: HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability
Source: BID
Type: UNKNOWN
40873
Source: CCN
Type: BID-40873
HP OpenView Network Node Manager CVE-2010-1964 Remote Buffer Overflow Vulnerability
Source: MISC
Type: UNKNOWN
http://www.zerodayinitiative.com/advisories/ZDI-10-108
Source: XF
Type: UNKNOWN
hp-ov-ovwebsnmpsrv-bo(59625)
Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [07-07-2010]
Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [03-23-2011]
Source: CCN
Type: ZDI-10-108
HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Remote Code Execution Vulnerability
Vulnerable Configuration:
Configuration 1
:
cpe:/a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:*:*:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*
OR
cpe:/a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*
Denotes that component is vulnerable
BACK
hp
openview network node manager 7.51
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.53
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.51 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -
hp
openview network node manager 7.53 -