CVE-2009-1420
Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when used with SNMP (aka HPOvNNM.HPOVSNMP) before 1.30.009 and MIB (aka HPOvNNM.HPOVMIB) before 1.30.009, allows remote attackers to execute arbitrary code…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when used with SNMP (aka HPOvNNM.HPOVSNMP) before 1.30.009 and MIB (aka HPOvNNM.HPOVMIB) before 1.30.009, allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.45% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- hp/openview network node manager
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=810
- http://marc.info/?l=bugtraq&m=124457320614552&w=2Patch
- http://secunia.com/advisories/35408Vendor Advisory
- http://securitytracker.com/id?1022360Patch
- http://www.securityfocus.com/bid/35267Patch
- http://www.vupen.com/english/advisories/2009/1549
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=810
- http://marc.info/?l=bugtraq&m=124457320614552&w=2Patch
- http://secunia.com/advisories/35408Vendor Advisory
- http://securitytracker.com/id?1022360Patch
- http://www.securityfocus.com/bid/35267Patch
- http://www.vupen.com/english/advisories/2009/1549
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.