First published: Fri Sep 02 2005(Updated: )
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP OpenView Network Node Manager | >=6.2<=7.50 | |
HP OpenView Network Node Manager | ||
HP OpenView Network Node Manager | =6.2 | |
HP OpenView Network Node Manager | =6.2 | |
HP OpenView Network Node Manager | =6.2 | |
HP OpenView Network Node Manager | =6.4 | |
HP OpenView Network Node Manager | =6.4 | |
HP OpenView Network Node Manager | =6.4 | |
HP OpenView Network Node Manager | =6.10 | |
HP OpenView Network Node Manager | =6.31 | |
HP OpenView Network Node Manager | =6.31 | |
HP OpenView Network Node Manager | =6.41 | |
HP OpenView Network Node Manager | =6.41 | |
HP OpenView Network Node Manager | =7.0.1 | |
HP OpenView Network Node Manager | =7.50 | |
HP OpenView Network Node Manager | =7.50 | |
HP OpenView Network Node Manager | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2773 is considered a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2005-2773, apply the latest patches provided by HP for the OpenView Network Node Manager.
CVE-2005-2773 affects HP OpenView Network Node Manager versions 6.2 through 7.50.
CVE-2005-2773 can be exploited through crafted input that utilizes shell metacharacters.
To mitigate CVE-2005-2773, implement strict input validation and limit access to the affected scripts.