PT-2010-3223 · Hewlett Packard · Hp Openview Network Node Manager
Published
2010-05-11
·
Updated
2018-10-10
·
CVE-2010-1550
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
HP OpenView Network Node Manager versions 7.01, 7.51, and 7.53
Description
The issue is related to a format string vulnerability in the ovet demandpoll.exe component. This vulnerability allows remote attackers to execute arbitrary code via format string specifiers in the
sel parameter.Recommendations
For HP OpenView Network Node Manager version 7.01, update to a version that includes the fix for this issue.
For HP OpenView Network Node Manager version 7.51, update to a version that includes the fix for this issue.
For HP OpenView Network Node Manager version 7.53, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the
sel parameter in the affected CGI endpoint until a patch is available.Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp Openview Network Node Manager