vendor:
OpenView
by:
bitform
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: OpenView
Affected Version From: 7.53
Affected Version To: 7.53
Patch Exists: YES
Related CWE: CVE-2010-1964
CPE: a:hp:openview:7.53
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2010
HP NNM 7.53 ovwebsnmpsrv.exe Buffer Overflow (SEH)
This is the result of research on CVE-2010-1964. Finding this vulnerability locally was trivial but getting a remote exploit via jovgraph.exe never quite worked out. Overflowing many of the other command line options will overwrite SEH as well (e.g. -demo). The buffer contains an alphanumeric bind shell.
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.