Vulnerabilities > CVE-2010-1964 - Remote Buffer Overflow vulnerability in HP OpenView Network Node Manager 7.51/7.53

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hp
nessus
exploit available
metasploit

Summary

Buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified parameters to jovgraph.exe, aka ZDI-CAN-683.

Vulnerable Configurations

Part Description Count
Application
Hp
10

Exploit-Db

  • descriptionHP NNM 7.53 ovwebsnmpsrv.exe Buffer Overflow (SEH). CVE-2010-1964. Local exploit for windows platform
    idEDB-ID:14256
    last seen2016-02-01
    modified2010-07-07
    published2010-07-07
    reporterbitform
    sourcehttps://www.exploit-db.com/download/14256/
    titleHP NNM 7.53 ovwebsnmpsrv.exe Buffer Overflow SEH
  • descriptionHP OpenView Network Node Manager ovwebsnmpsrv.exe main Buffer Overflow. CVE-2010-1964. Remote exploit for windows platform
    idEDB-ID:17041
    last seen2016-02-02
    modified2011-03-23
    published2011-03-23
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/17041/
    titleHP OpenView Network Node Manager ovwebsnmpsrv.exe main Buffer Overflow

Metasploit

  • descriptionThis module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53 prior to NNM_01203. By specifying a long 'arg' parameter when executing the 'jovgraph.exe' CGI program, an attacker can cause a stack-based buffer overflow and execute arbitrary code. This vulnerability is triggerable via either a GET or POST request. The buffer being written to is 1024 bytes in size. It is important to note that this vulnerability must be exploited by overwriting SEH. Otherwise, CVE-2010-1961 is triggered! The vulnerable code is within the "main" function within "ovwebsnmpsrv.exe" with a timestamp prior to April 7th, 2010. There are no stack cookies, so exploitation is easily achieved by overwriting SEH structures. There exists some unreliability when running this exploit. It is not completely clear why at this time, but may be related to OVWDB or session management. Also, on some attempts OV NNM may report invalid characters in the URL. It is not clear what is causing this either.
    idMSF:EXPLOIT/WINDOWS/HTTP/HP_NNM_OVWEBSNMPSRV_MAIN
    last seen2020-06-14
    modified1976-01-01
    published1976-01-01
    referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1964
    reporterRapid7
    sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/hp_nnm_ovwebsnmpsrv_main.rb
    titleHP OpenView Network Node Manager ovwebsnmpsrv.exe main Buffer Overflow
  • descriptionThis module exploits a stack buffer overflow in HP OpenView Network Node Manager 7.53 prior to NNM_01203. By specifying a long 'arg' parameter when executing the 'jovgraph.exe' CGI program, an attacker can cause a stack-based buffer overflow and execute arbitrary code. This vulnerability is triggerable via either a GET or POST request. It is interesting to note that this vulnerability cannot be exploited by overwriting SEH, since attempting to would trigger CVE-2010-1964. The vulnerable code is within a sub-function called from "main" within "ovwebsnmpsrv.exe" with a timestamp prior to April 7th, 2010. This function contains a 256 byte stack buffer which is passed to the "getProxiedStorageAddress" function within ovutil.dll. When processing the address results in an error, the buffer is overflowed in a call to sprintf_new. There are no stack cookies present, so exploitation is easily achieved by overwriting the saved return address. There exists some unreliability when running this exploit. It is not completely clear why at this time, but may be related to OVWDB or session management. Also, on some attempts OV NNM may report invalid characters in the URL. It is not clear what is causing this either.
    idMSF:EXPLOIT/WINDOWS/HTTP/HP_NNM_OVWEBSNMPSRV_OVUTIL
    last seen2020-05-26
    modified2017-07-24
    published2011-03-23
    references
    reporterRapid7
    sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/hp_nnm_ovwebsnmpsrv_ovutil.rb
    titleHP OpenView Network Node Manager ovwebsnmpsrv.exe ovutil Buffer Overflow

Nessus

  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHSS_40708.NASL
    descriptions700_800 11.X OV NNM7.53 IA-64 Intermediate Patch 26 : The remote HP-UX host is affected by multiple vulnerabilities : - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2010-1550 (SSRT090225, ZDI-CAN-563) CVE-2010-1551 (SSRT090226, ZDI-CAN-564) CVE-2010-1552 (SSRT090227, ZDI-CAN-566) CVE-2010-1553 (SSRT090228, ZDI-CAN-573) CVE-2010-1554 (SSRT090229, ZDI-CAN-574) CVE-2010-1555 (SSRT090230, ZDI-CAN-575). (HPSBMA02527 SSRT010098) - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code under the context of the user running the web server. References: CVE-2010-1964 (SSRT100026, ZDI-CAN-683) CVE-2010-1960 (SSRT100027, ZDI-CAN-684) CVE-2010-1961 (SSRT100028, ZDI-CAN-685). - A potential security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code under the context of the user running the web server.
    last seen2020-06-01
    modified2020-06-02
    plugin id46348
    published2010-05-17
    reporterThis script is Copyright (C) 2010-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/46348
    titleHP-UX PHSS_40708 : s700_800 11.X OV NNM7.53 IA-64 Intermediate Patch 26
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHSS_40707.NASL
    descriptions700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 26 : The remote HP-UX host is affected by multiple vulnerabilities : - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code under the context of the user running the web server. References: CVE-2010-1964 (SSRT100026, ZDI-CAN-683) CVE-2010-1960 (SSRT100027, ZDI-CAN-684) CVE-2010-1961 (SSRT100028, ZDI-CAN-685). - Potential security vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code. References: CVE-2010-1550 (SSRT090225, ZDI-CAN-563) CVE-2010-1551 (SSRT090226, ZDI-CAN-564) CVE-2010-1552 (SSRT090227, ZDI-CAN-566) CVE-2010-1553 (SSRT090228, ZDI-CAN-573) CVE-2010-1554 (SSRT090229, ZDI-CAN-574) CVE-2010-1555 (SSRT090230, ZDI-CAN-575). (HPSBMA02527 SSRT010098) - A potential security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code under the context of the user running the web server.
    last seen2020-06-01
    modified2020-06-02
    plugin id46347
    published2010-05-17
    reporterThis script is Copyright (C) 2010-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/46347
    titleHP-UX PHSS_40707 : s700_800 11.X OV NNM7.53 PA-RISC Intermediate Patch 26

Packetstorm

Seebug

  • bulletinFamilyexploit
    descriptionBUGTRAQ ID: 40873 CVE ID: CVE-2010-1964 HP OpenView网络节点管理器(OV NNM)是HP公司开发和维护的网络管理系统软件,具有强大的网络节点管理功能。 OpenView网络节点管理器中可通过jovgraph.exe CGI程序到达的ovwebsnmpsrv.exe服务进程中存在缓冲区溢出漏洞。如果远程用户通过HTTP请求向变量传送了超大值,则main()函数中的strcpy调用就可能溢出静态缓冲区,导致以运行webserver用户的权限执行任意代码。 HP OpenView Network Node Manager 7.53 HP OpenView Network Node Manager 7.51 厂商补丁: HP -- HP已经为此发布了一个安全公告(HPSBMA02537)以及相应补丁: HPSBMA02537:SSRT010027 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Execution of Arbitrary Code 链接:https://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02217439&admit=109447626+127624536
    idSSV:19930
    last seen2017-11-19
    modified2010-07-08
    published2010-07-08
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-19930
    titleHP OpenView网络节点管理器ovwebsnmpsrv.exe远程溢出漏洞
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:71522
    last seen2017-11-19
    modified2014-07-01
    published2014-07-01
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-71522
    titleHP OpenView Network Node Manager ovwebsnmpsrv.exe ovutil Buffer Overflow
  • bulletinFamilyexploit
    descriptionNo description provided by source.
    idSSV:19921
    last seen2017-11-19
    modified2010-07-07
    published2010-07-07
    reporterRoot
    sourcehttps://www.seebug.org/vuldb/ssvid-19921
    titleHP NNM 7.53 ovwebsnmpsrv.exe Buffer Overflow (SEH)