PT-2014-4828 · Hewlett Packard · Hp Network Node Manager I

Published

2014-09-11

·

Updated

2017-08-29

·

CVE-2014-2624

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Network Node Manager i (NNMi) versions 9.0x through 9.2x
Description The issue allows remote attackers to execute arbitrary code via unknown vectors. It is related to the ovopi.dll component and involves various vulnerabilities, including stack buffer overflows and heap buffer overflows, which can be triggered by different options such as -L, -T, and -D, or by specific commands like Command 685.
Recommendations For HP Network Node Manager i (NNMi) versions 9.0x through 9.2x, consider disabling the ovopi.dll component or restricting access to it until a patch is available. Avoid using options -L, -T, and -D, and avoid executing Command 685 in the affected API endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-2624
ZDI-14-305
ZDI-14-335
ZDI-14-336
ZDI-14-337
ZDI-14-338
ZDI-14-339
ZDI-14-340
ZDI-14-341
ZDI-14-342
ZDI-14-343

Affected Products

Hp Network Node Manager I