cbcvebase.
CVE-2005-2773
published 2005-09-02

CVE-2005-2773: HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to…

PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
74.09%
99.4th percentile
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

Affected

1 ranges
VendorProductVersion rangeFixed in
hpopenview_network_node_manager6.2 – 7.50

Detection & IOCsextracted from sources · hover to see the quote

url/OvCgi/connectedNodes.ovpl?node=a|command|
path/OvCgi/connectedNodes.ovpl
path/OvCgi/connectedNodes.ovpl
port3443
  • Detect shell metacharacter injection in the 'node' GET parameter of HP OpenView CGI scripts: connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. Look for pipe (|), semicolon (;), or other shell metacharacters in the node parameter value.
  • Alert on HTTP GET requests to /OvCgi/connectedNodes.ovpl where the 'node' query parameter contains shell metacharacters such as '|' or ';'.
  • Monitor inbound connections to TCP port 3443 targeting HP OpenView NNM CGI paths, as the exploit hardcodes this port for communication.
  • ·The Metasploit module payload compatibility is restricted to specific command types; generic/perl/telnet payloads are required, limiting payload flexibility.
  • ·The exploit payload space is limited to 1024 bytes with NOP generation disabled, constraining the size of injected commands.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.