Vulnerability record · CVE-2007-6204 · published 13 December 2007
CVE-2007-6204: HP OpenView Network Node Manager stack buffer overflow in multiple CGI executables
Hp · Openview Network Node Manager
HP OpenView Network Node Manager (OV NNM) versions 6.41, 7.01 and 7.51 contain multiple stack-based buffer overflows in ovlogin.exe, OpenView5.exe, snmpviewer.exe and webappmon.exe. Long arguments, such as the Action parameter to OpenView5.exe, can overwrite the stack and allow remote code execution. The flaw is remotely reachable and carries a CVSS v2 score of 10.0.
Description
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS v2 10.0 with network reachability, no authentication, and public exploit references make this a high-impact, readily exploitable flaw despite the absence of KEV listing.
What it is
HP OpenView Network Node Manager (OV NNM) versions 6.41, 7.01 and 7.51 contain multiple stack-based buffer overflows in ovlogin.exe, OpenView5.exe, snmpviewer.exe and webappmon.exe. Long arguments, such as the Action parameter to OpenView5.exe, can overwrite the stack and allow remote code execution. The flaw is remotely reachable and carries a CVSS v2 score of 10.0.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected service, which typically runs with elevated rights on the management server. This can lead to full compromise of the NNM host and any managed network context it holds.
Attack surface
The vulnerable executables are network-facing CGI components of OV NNM, reached over HTTP with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). No user interaction is indicated by the description or vector.
Exploitation
The record is not listed in CISA KEV, but EPSS is 0.69613 (99.33rd percentile) and references include an Exploit tag on SecurityFocus BID 26741 and an Exploit-DB entry, indicating public exploit material exists.
What to do
- Apply the HP vendor patch referenced in the HP support document and SecurityFocus BID 26741.
- If patching is not immediately possible, restrict network access to the NNM web interface and CGI executables to trusted management hosts only.
- Disable or remove unused CGI components such as ovlogin.exe, OpenView5.exe, snmpviewer.exe and webappmon.exe where they are not required.
- Run the NNM service under a least-privilege account and isolate the management server on a segmented network.
- Monitor vendor advisories for updated guidance since the product line is legacy and may be end-of-support.
Detection
- Inspect HTTP request logs for unusually long parameters, especially Action values sent to OpenView5.exe and other listed CGI binaries.
- Alert on crashes or restarts of ovlogin.exe, OpenView5.exe, snmpviewer.exe or webappmon.exe, which may indicate failed overflow attempts.
- Use network IDS signatures for known exploit patterns against the NNM CGI endpoints and review traffic to the management interface from unexpected sources.
- Correlate process creation of the affected executables with anomalous child processes or outbound connections from the NNM host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-6204 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-6204), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.