← Vulnerability feed

Vulnerability record · CVE-2005-2773 · published 2 September 2005

CVE-2005-2773: HP OpenView Network Node Manager command injection in multiple .ovpl scripts

Hp · Openview Network Node Manager

HP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. An unauthenticated remote attacker can inject shell metacharacters to run arbitrary commands on the server. The flaw is severe because it gives full control of a network management host that typically holds broad visibility and credentials across the managed estate.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 75% · top 0.5% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
75%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS 3.1 score of 9.8, KEV listing, and very high EPSS probability make this an urgent patch target.

What it is

HP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. An unauthenticated remote attacker can inject shell metacharacters to run arbitrary commands on the server. The flaw is severe because it gives full control of a network management host that typically holds broad visibility and credentials across the managed estate.

Impact

An attacker gains arbitrary command execution with the privileges of the NNM web service, allowing full compromise of the host and any credentials or trust relationships it holds. From there, lateral movement into managed network devices and other monitored systems is likely.

Attack surface

Reached over the network through the NNM web interface by sending crafted requests to the affected .ovpl scripts; the CVSS vector shows no privileges or user interaction required. No authentication is indicated as a precondition in the record.

Exploitation

Listed in CISA KEV since 2022-03-25 with a required action to apply vendor updates, and EPSS is 0.74592 (99.5th percentile), indicating high real-world exploitation likelihood. A public exploit reference is tagged in the Bugtraq mailing list entry.

What to do

  • Apply the vendor updates referenced in the CISA KEV required action; treat this as the first step.
  • If NNM 6.2 through 7.50 cannot be patched or upgraded, isolate the management server from untrusted networks and restrict access to the web interface.
  • Place the NNM web interface behind an authenticating reverse proxy or VPN so only trusted administrators can reach the .ovpl endpoints.
  • Audit the affected scripts (connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, ecscmg.ovpl) for input validation and remove shell invocation of user-controlled parameters where feasible.
  • Monitor and rotate any credentials stored or used on the NNM host, since compromise would expose them.

Detection

  • Inspect web server and NNM logs for requests to connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl containing shell metacharacters (;, |, `, $(), &&) in the node parameter.
  • Alert on child processes spawned by the NNM web service (for example shell or command interpreters) that are unexpected for normal operation.
  • Baseline outbound connections from the NNM host and alert on new destinations, especially to managed network segments.
  • Review host and application logs on the NNM server for command execution artifacts and unusual file writes around the time of suspicious web requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2005-2773 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "HP OpenView Network Node Manager Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2773 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3167HP OpenView Network Node Manager remote code execution flawHP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code throug…EPSS 65%analysed10.0CVE-2011-3165Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-3166Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-0261Hp openview network node manager vulnerabilityUnspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute a…EPSS 16%10.0CVE-2011-0262Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows r…EPSS 17%10.0CVE-2011-0263Hp openview network node manager memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attacke…EPSS 17%10.0CVE-2011-0264Hp openview network node manager memory buffer overflow vulnerabilityStack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary cod…EPSS 17%10.0CVE-2011-0265Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via …EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2005-2773), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.