CVE-2007-1093
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.87% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- hitachi/cm2-network node manager · hitachi/cm2-network node manager 250 · hitachi/jp1-cm2-network node manager · hitachi/jp1-cm2-network node manager 250 · hitachi/jp1-cm2-network node manager starter · hitachi/jp1-cm2-network node manager starter 250
- Source
- cve@mitre.org
References
- http://osvdb.org/33528
- http://osvdb.org/33529
- http://secunia.com/advisories/24276Patch, Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.htmlPatch
- http://www.vupen.com/english/advisories/2007/0739
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32682
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32683
- http://osvdb.org/33528
- http://osvdb.org/33529
- http://secunia.com/advisories/24276Patch, Vendor Advisory
- http://www.hitachi-support.com/security_e/vuls_e/HS07-002_e/index-e.htmlPatch
- http://www.vupen.com/english/advisories/2007/0739
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32682
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32683
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.