Bird_banner_small4
HP OpenView NNM getnnmdata.exe CGI Hostname Parameter Buffer Overflow
TSL ID TSL20100512-06
CVE ID(s) CVE-2010-1555
Severity Critical
Description

A code execution vulnerability exists in HP OpenView Network Node Manager (NNM). The vulnerability is due to a boundary error in getnnmdata.exe when processing the Hostname variable sent in a crafted HTTP request. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to a target server, potentially causing arbitrary code to be injected and executed in the security context of the getnnmdata.exe process.

In an attack scenario, where arbitrary code is injected and executed on the target machine, the behavior of the target is dependent on the intention of the malicious code.

HP provides a patch to address this vulnerability. Mitigation and patch details are available at:

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02153379

Affected Products
  • HP OpenView Network Node Manager (OV NNM) 7.01
  • HP OpenView Network Node Manager (OV NNM) 7.51
  • HP OpenView Network Node Manager (OV NNM) 7.53
CVSS Score Base 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P):
  • Access vector is NETWORK
  • Access complexity is LOW
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is PARTIAL
  • Impact of this vulnerability on data integrity is PARTIAL
  • Impact of this vulnerability on data availability is PARTIAL
Temporal 6.2 (E:F/RL:OF/RC:C):
  • The exploitability level of this vulnerability is FUNCTIONAL
  • The remediation level of this vulnerability is OFFICIAL FIX
  • The report confidence level of this vulnerability is CONFIRMED
Identifiers
ZDI
References http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02153379
http://www.exploit-db.com/exploits/17047/
Related Threats