CVE-2005-2773
published 2005-09-02CVE-2005-2773: HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to…
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
74.09%
99.4th percentile
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | openview_network_node_manager | 6.2 – 7.50 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect shell metacharacter injection in the 'node' GET parameter of HP OpenView CGI scripts: connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. Look for pipe (|), semicolon (;), or other shell metacharacters in the node parameter value. ↗
- →Alert on HTTP GET requests to /OvCgi/connectedNodes.ovpl where the 'node' query parameter contains shell metacharacters such as '|' or ';'. ↗
- →Monitor inbound connections to TCP port 3443 targeting HP OpenView NNM CGI paths, as the exploit hardcodes this port for communication. ↗
- ·The Metasploit module payload compatibility is restricted to specific command types; generic/perl/telnet payloads are required, limiting payload flexibility. ↗
- ·The exploit payload space is limited to 1024 bytes with NOP generation disabled, constraining the size of injected commands. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HP OpenView Network Node Manager up to 6.2 node privileges management (EDB-1188 / Nessus ID 19555)
vuldb·2026-04-22·CVSS 9.8
CVE-2005-2773 [CRITICAL] HP OpenView Network Node Manager up to 6.2 node privileges management (EDB-1188 / Nessus ID 19555)
A vulnerability has been found in HP OpenView Network Node Manager up to 6.2 and classified as critical. The affected element is an unknown function of the component Node Manager. This manipulation of the argument node causes improper privilege management.
This vulnerability is tracked as CVE-2005-2773. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-xqgm-4493-f736: HP OpenView Network Node Manager 6
ghsa_unreviewed·2022-05-01
CVE-2005-2773 [HIGH] CWE-77 GHSA-xqgm-4493-f736: HP OpenView Network Node Manager 6
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
VulnCheck
HP OpenView Network Node Manager Remote Code Execution Vulnerability
vulncheck·2005·CVSS 9.8
CVE-2005-2773 [CRITICAL] HP OpenView Network Node Manager Remote Code Execution Vulnerability
HP OpenView Network Node Manager Remote Code Execution Vulnerability
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Affected: Hewlett Packard (HP) OpenView Network Node Manager
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.researchgate.net/publication/348602660_An_analysis_of_the_use_of_CVEs_by_IoT_malware; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-04-15
CISA
HP OpenView Network Node Manager Remote Code Execution Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2005-2773 [CRITICAL] HP OpenView Network Node Manager Remote Code Execution Vulnerability
Vulnerability: HP OpenView Network Node Manager Remote Code Execution Vulnerability
Affected: Hewlett Packard (HP) OpenView Network Node Manager
HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2005-2773
Remediation Due Date: 2022-04-15
No detection rules found.
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'connectedNodes.ovp'l Remote Command Execution (Metasploit)
exploitdb·2010-07-03
CVE-2005-2773 HP OpenView Network Node Manager (OV NNM) - 'connectedNodes.ovp'l Remote Command Execution (Metasploit)
HP OpenView Network Node Manager (OV NNM) - 'connectedNodes.ovp'l Remote Command Execution (Metasploit)
---
##
# $Id: openview_connectednodes_exec.rb 9671 2010-07-03 06:21:31Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'HP Openview connectedNodes.ovpl Remote Command Execution',
'Description' => %q{
This module exploits an arbitrary command execution vulnerability in the
HP OpenView connectedNodes.ovpl CGI application. The results of the command
will be displayed to the screen.
},
'Author' => [ 'Valerio Tesei ', 'hdm' ],
'License
Exploit-DB
HP OpenView Network Node Manager 7.50 - Remote Command Execution
exploitdb·2005-08-30
CVE-2005-2773 HP OpenView Network Node Manager 7.50 - Remote Command Execution
HP OpenView Network Node Manager 7.50 - Remote Command Execution
---
/*
Web Browser info:
/OvCgi/connectedNodes.ovpl?node=a|command|
/str0ke
*/
/*
##################################################################################
# HP OpenView Network Node Manager 6.2, 6.4, 7.01, 7.50 Remote Command Execution #
##################################################################################
Name: HP OV NNM Remote Command Execution Exploit
File: HP_OV_NNM_RCE.c
Description: Exploit
Author: Lympex
Contact:
+ Web: http://l-bytes.net
+ Mail: lympex[at]gmail[dot]com
Date: 30/08/2005
Extra: Compiled with Visual C++ 6.0
############################################################################
#SecurityTracker Alert ID: 1014791 #
#SecurityTracker URL: http://securitytracker.com/id?101479
Metasploit
HP Openview connectedNodes.ovpl Remote Command Execution
metasploit
HP Openview connectedNodes.ovpl Remote Command Execution
HP Openview connectedNodes.ovpl Remote Command Execution
This module exploits an arbitrary command execution vulnerability in the HP OpenView connectedNodes.ovpl CGI application. The results of the command will be displayed to the screen.
Unit42
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
blogs_unit42·2019-12-13
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
Threat Research Center
Threat Research
Malware
## Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
Ruchna Nigam
Published: December 13, 2019
Malware
Threat Research
Vulnerabilities
Echobot
IoT
IoT Vulnerability
Mirai
Mirai variant
## Executive Summary
Since the discovery of the Mirai variant using the binary name ECHOBOT in May 2019, it has resurfaced from time to time, using new infrastructure, and more remarkably, adding to the list of vulnerabilities it scans for, as a means to increase its attack surface with each evolution.
Unlike other Mirai variants, this particular variant stands out for the sheer number of exploits it incorporates, with the latest version having a total of 71 unique exploits, 13 of which haven’t been seen exploite
Unit42
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
blogs_unit42·2019-12-13
Mirai Variant ECHOBOT Resurfaces with 13 Previously Unexploited Vulnerabilities
## Executive Summary
Since the discovery of the Mirai variant using the binary name ECHOBOT in May 2019, it has resurfaced from time to time, using new infrastructure, and more remarkably, adding to the list of vulnerabilities it scans for, as a means to increase its attack surface with each evolution.
Unlike other Mirai variants, this particular variant stands out for the sheer number of exploits it incorporates, with the latest version having a total of 71 unique exploits, 13 of which haven’t been seen exploited in the wild until now, ranging from extremely old CVEs from as long back as 2003, to recent vulnerabilities made public as recently as early December 2019. Based on this seemingly odd choice, one could risk a guess that the attackers could potentially be aiming for the sweet sp
http://marc.info/?l=bugtraq&m=112499121725662&w=2http://secunia.com/advisories/16555/http://www.securityfocus.com/advisories/9150http://www.securityfocus.com/bid/14662https://exchange.xforce.ibmcloud.com/vulnerabilities/21999http://marc.info/?l=bugtraq&m=112499121725662&w=2http://secunia.com/advisories/16555/http://www.securityfocus.com/advisories/9150http://www.securityfocus.com/bid/14662https://exchange.xforce.ibmcloud.com/vulnerabilities/21999https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773
2005-09-02
Published
2022-03-25
Added to CISA KEV
Exploited in the wild