| TSL ID | TSL20100512-06 |
| CVE ID(s) | CVE-2010-1555 |
| Severity | Critical |
| Description | A code execution vulnerability exists in HP OpenView Network Node Manager (NNM). The vulnerability is due to a boundary error in getnnmdata.exe when processing the Hostname variable sent in a crafted HTTP request. A remote unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request to a target server, potentially causing arbitrary code to be injected and executed in the security context of the getnnmdata.exe process. In an attack scenario, where arbitrary code is injected and executed on the target machine, the behavior of the target is dependent on the intention of the malicious code. HP provides a patch to address this vulnerability. Mitigation and patch details are available at: http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02153379 |
| Affected Products |
|
| CVSS Score |
Base 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P):
|
| Identifiers | |
| References |
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02153379 http://www.exploit-db.com/exploits/17047/ |
| Related Threats |