CVE-2011-0271: OS Command Injection
Published Jan 13, 2011
·Updated
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."
Affected Software
2 affected components
Hewlett Packard OpenView Network Node Manager=7.51
Hewlett Packard OpenView Network Node Manager=7.53
Event History
Jan 13, 2011
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0271?
CVE-2011-0271 has been classified as critical due to its potential for remote code execution.
2
How do I fix CVE-2011-0271?
To mitigate CVE-2011-0271, upgrade HP OpenView Network Node Manager to version 7.54 or later.
3
What systems are affected by CVE-2011-0271?
CVE-2011-0271 affects HP OpenView Network Node Manager versions 7.51 and 7.53.
4
Can CVE-2011-0271 be exploited remotely?
Yes, CVE-2011-0271 can be exploited remotely by attackers to execute arbitrary commands.
5
What is the nature of the vulnerability in CVE-2011-0271?
CVE-2011-0271 is a command injection vulnerability due to improper validation of an unspecified parameter.