Vulnerability record · CVE-2005-2773 · published 2 September 2005
CVE-2005-2773: HP OpenView Network Node Manager command injection in multiple .ovpl scripts
Hp · Openview Network Node Manager
HP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. An unauthenticated remote attacker can inject shell metacharacters to run arbitrary commands on the server. The flaw is severe because it gives full control of a network management host that typically holds broad visibility and credentials across the managed estate.
Description
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 3.1 score of 9.8, KEV listing, and very high EPSS probability make this an urgent patch target.
What it is
HP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl. An unauthenticated remote attacker can inject shell metacharacters to run arbitrary commands on the server. The flaw is severe because it gives full control of a network management host that typically holds broad visibility and credentials across the managed estate.
Impact
An attacker gains arbitrary command execution with the privileges of the NNM web service, allowing full compromise of the host and any credentials or trust relationships it holds. From there, lateral movement into managed network devices and other monitored systems is likely.
Attack surface
Reached over the network through the NNM web interface by sending crafted requests to the affected .ovpl scripts; the CVSS vector shows no privileges or user interaction required. No authentication is indicated as a precondition in the record.
Exploitation
Listed in CISA KEV since 2022-03-25 with a required action to apply vendor updates, and EPSS is 0.74592 (99.5th percentile), indicating high real-world exploitation likelihood. A public exploit reference is tagged in the Bugtraq mailing list entry.
What to do
- Apply the vendor updates referenced in the CISA KEV required action; treat this as the first step.
- If NNM 6.2 through 7.50 cannot be patched or upgraded, isolate the management server from untrusted networks and restrict access to the web interface.
- Place the NNM web interface behind an authenticating reverse proxy or VPN so only trusted administrators can reach the .ovpl endpoints.
- Audit the affected scripts (connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, ecscmg.ovpl) for input validation and remove shell invocation of user-controlled parameters where feasible.
- Monitor and rotate any credentials stored or used on the NNM host, since compromise would expose them.
Detection
- Inspect web server and NNM logs for requests to connectedNodes.ovpl, cdpView.ovpl, freeIPaddrs.ovpl, and ecscmg.ovpl containing shell metacharacters (;, |, `, $(), &&) in the node parameter.
- Alert on child processes spawned by the NNM web service (for example shell or command interpreters) that are unexpected for normal operation.
- Baseline outbound connections from the NNM host and alert on new destinations, especially to managed network segments.
- Review host and application logs on the NNM server for command execution artifacts and unusual file writes around the time of suspicious web requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2005-2773 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "HP OpenView Network Node Manager Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=112499121725662&w=2 | ExploitIssue TrackingMailing List |
| http://secunia.com/advisories/16555/ | Not Applicable |
| http://www.securityfocus.com/advisories/9150 | Broken Link |
| http://www.securityfocus.com/bid/14662 | Broken Link |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/21999 | Third Party Advisory |
| http://marc.info/?l=bugtraq&m=112499121725662&w=2 | ExploitIssue TrackingMailing List |
| http://secunia.com/advisories/16555/ | Not Applicable |
| http://www.securityfocus.com/advisories/9150 | Broken Link |
| http://www.securityfocus.com/bid/14662 | Broken Link |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/21999 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2005-2773 | US Government Resource |
Track CVE-2005-2773 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2773), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.