HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
BID:37300
Info
HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
| Bugtraq ID: | 37300 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3845 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2009 12:00AM |
| Updated: | May 05 2010 05:12PM |
| Credit: | Dyon Balding, Secunia Research |
| Vulnerable: |
HP OpenView Network Node Manager 7.50 Windows 2000/XP HP OpenView Network Node Manager 7.50 Solaris HP OpenView Network Node Manager 7.50 Linux HP OpenView Network Node Manager 7.50 HP-UX 11.X HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 HP OpenView Network Node Manager 7.50 HP OpenView Network Node Manager 7.01 |
| Not Vulnerable: | |
Discussion
HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
HP OpenView Network Node Manager (NNM) is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows an attacker to execute arbitrary code with SYSTEM-level privileges, completely compromising affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects NNM 7.01, 7.51, and 7.53.
NOTE: This issue was previously covered in BID 37261 (HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities), but has been assigned its own record to better document it.
HP OpenView Network Node Manager (NNM) is prone to a remote code-execution vulnerability.
Successfully exploiting this issue allows an attacker to execute arbitrary code with SYSTEM-level privileges, completely compromising affected computers. Failed exploit attempts will result in a denial-of-service condition.
This issue affects NNM 7.01, 7.51, and 7.53.
NOTE: This issue was previously covered in BID 37261 (HP OpenView Network Node Manager Multiple Remote Code Execution Vulnerabilities), but has been assigned its own record to better document it.
Exploit / POC
HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for details.
HP OpenView Network Node Manager 7.53
HP OpenView Network Node Manager 7.01
Solution:
Vendor updates are available. Please see the referenced advisory for details.
HP OpenView Network Node Manager 7.53
-
HP LXOV_00093
Linux RedHatAS2.1
http://support.openview.hp.com/selfsolve/patches -
HP LXOV_00094
Linux RedHat4AS-x86_64
http://support.openview.hp.com/selfsolve/patches -
HP NNM_01197
Windows
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39245
HP-UX (PA)
http://support.openview.hp.com/selfsolve/patches -
HP PHSS_39246
HP-UX (IA)
http://support.openview.hp.com/selfsolve/patches -
HP PSOV_03519
Solaris
http://support.openview.hp.com/selfsolve/patches
HP OpenView Network Node Manager 7.01
-
HP SSRT080125.701_IP12.hotfix.tar.gz
Windows
ftp://ss080125:[email protected]
References
HP OpenView Network Node Manager Perl CGI Executables Remote Code Execution Vulnerability
References:
References: