CVE-2008-3544
published 2008-10-13CVE-2008-3544: Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote…
PriorityP263critical9CVSS 2.0
AVNACLAuNCPIPAC
EXPLOIT
EPSS
18.04%
96.9th percentile
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect format string attack payload sent to TCP port 2953 targeting ovalarmsrv; look for format specifiers such as %n and %s in the request stream ↗
- →Detect stack-based buffer overflow attempts on TCP port 2954 via REQUEST_RESTORE_STATE (opcode 62) with a string parameter longer than 512 bytes ↗
- →Monitor for ovalarmsrv process consuming CPU at 100% following receipt of invalid values on ports 2953/2954, indicating a denial-of-service condition ↗
- →Alert on the error string 'Connection Refused; Data in listener port corrupt:' appearing in logs, which reflects the format string vulnerability trigger path in ovalarmsrv ↗
- ·Affected versions include OV NNM 7.51 (confirmed) and possibly 7.01, 7.50, and 7.53; the exploit-db PoC targets 7.53 specifically ↗
- ·No vendor fix was available at the time of disclosure (2008-04-07) ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79h2-q588-8g28: Unspecified vulnerability in ovtopmd in HP OpenView Network Node Manager (OV NNM) 7
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2008-3545 [MEDIUM] GHSA-79h2-q588-8g28: Unspecified vulnerability in ovtopmd in HP OpenView Network Node Manager (OV NNM) 7
Unspecified vulnerability in ovtopmd in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536, CVE-2008-3537, and CVE-2008-3544. NOTE: due to insufficient details from the vendor, it is not clear whether this is the same as CVE-2008-1853.
GHSA
GHSA-555m-5vqw-mv38: Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7
ghsa_unreviewed·2022-05-02
CVE-2008-3544 [HIGH] CWE-119 GHSA-555m-5vqw-mv38: Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.
No detection rules found.
No writeups or analysis indexed.
http://aluigi.altervista.org/adv/closedview_old-adv.txthttp://downloads.securityfocus.com/vulnerabilities/exploits/28668.chttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01537275http://secunia.com/advisories/31688http://securityreason.com/securityalert/4397http://www.securityfocus.com/archive/1/490541http://www.securityfocus.com/bid/28668http://aluigi.altervista.org/adv/closedview_old-adv.txthttp://downloads.securityfocus.com/vulnerabilities/exploits/28668.chttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01537275http://secunia.com/advisories/31688http://securityreason.com/securityalert/4397http://www.securityfocus.com/archive/1/490541http://www.securityfocus.com/bid/28668
2008-10-13
Published