Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-2703

CWE-119Buffer Overflow6 documents4 sources
Severity
10.0CRITICAL
EPSS
79.6%
top 0.91%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 28
Latest updateMay 14

Description

Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rcv5-53xq-8xw7: Stack-based buffer overflow in the execvp_nc function in the ov2022-05-14
CVEList
CVE-2010-2703: Stack-based buffer overflow in the execvp_nc function in the ov2010-07-27

💥Exploits & PoCs

3
Exploit-DB
HP Network Node Manager (NMM) - CGI 'webappmon.exe execvp' Remote Buffer Overflow (Metasploit)2011-03-23
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'webappmon.exe execvp_nc' Remote Code Execution2010-09-06
Exploit-DB
Novell Groupwise Messenger Client - Remote Buffer Overflow (Metasploit)2010-06-22