vendor:
OpenView Network Node Manager
by:
Luigi Auriemma
7.5
CVSS
HIGH
Format String, Buffer Overflow, Denial of Service
134, 119, 400
CWE
Product Name: OpenView Network Node Manager
Affected Version From: <= 7.53
Affected Version To: <= 7.53
Patch Exists: YES
Related CWE: N/A
CPE: a:hp:openview_network_node_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Solaris, Linux, HP-UX
2008
HP OpenView Network Node Manager Vulnerability
The ovalarmsrv.exe process listening on port 2953 is affected by a format string vulnerability caused by the calling of ov.fprintf_new (which then calls vsprintf) using the final message without a format argument. The same process listens also on port 2954 where are handled some types of requests using specific sscanf formats. The same process is affected by a Denial of Service caused by the sending of a malformed packet on port 2954.
Mitigation:
Upgrade to the latest version of HP OpenView Network Node Manager