Vulnerability record · CVE-2008-1697 · published 8 April 2008
CVE-2008-1697: HP OpenView Network Node Manager ovwparser.dll stack buffer overflow
Hp · Openview Network Node Manager
A stack-based buffer overflow exists in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51 and earlier. A long URI in an HTTP request handled by ovas.exe, such as a topology/homeBaseView request, overflows the buffer and can lead to remote code execution. The flaw is remotely reachable and carries a maximum CVSS 2.0 base score of 10.
Description
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain topology/homeBaseView request. NOTE: some of these details are obtained from third party information.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityMaximum CVSS 2.0 score of 10 with network reachability, no authentication, and public exploit code plus very high EPSS probability make this an urgent fix despite the absence of KEV listing.
What it is
A stack-based buffer overflow exists in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51 and earlier. A long URI in an HTTP request handled by ovas.exe, such as a topology/homeBaseView request, overflows the buffer and can lead to remote code execution. The flaw is remotely reachable and carries a maximum CVSS 2.0 base score of 10.
Impact
An unauthenticated remote attacker can execute arbitrary code on the NNM server, typically with the privileges of the ovas.exe service. That gives full compromise of the management host, including confidentiality, integrity and availability impact.
Attack surface
Reached over the network via HTTP requests to the ovas.exe service on the NNM host; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The crafted URI is processed by ovwparser.dll during request parsing.
Exploitation
Public exploit code is referenced (Offensive Security and Exploit-DB entries), and EPSS shows a 30-day probability of 0.74345 at the 99.466th percentile, indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.
What to do
- Apply the HP vendor patch for OV NNM 7.53/7.51 and earlier as referenced in the SecurityFocus and vendor advisories.
- If patching is not immediately possible, restrict network access to the ovas.exe HTTP service to trusted management hosts only.
- Place the NNM server behind a filtering proxy or WAF that rejects oversized or malformed URIs.
- Monitor and log HTTP requests to ovas.exe for unusually long URI values.
- Retire or isolate end-of-life NNM versions that no longer receive vendor fixes.
Detection
- Inspect HTTP request logs for ovas.exe for abnormally long URI strings or topology/homeBaseView requests with oversized parameters.
- Alert on crashes or restarts of ovas.exe or ovwparser.dll-related processes on NNM hosts.
- Hunt for exploit payload patterns from the public Offensive Security and Exploit-DB PoCs in network traffic to the NNM service.
- Monitor for unexpected child processes or outbound connections originating from the NNM server after HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-1697 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-1697), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.