← Vulnerability feed

Vulnerability record · CVE-2008-1697 · published 8 April 2008

CVE-2008-1697: HP OpenView Network Node Manager ovwparser.dll stack buffer overflow

Hp · Openview Network Node Manager

A stack-based buffer overflow exists in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51 and earlier. A long URI in an HTTP request handled by ovas.exe, such as a topology/homeBaseView request, overflows the buffer and can lead to remote code execution. The flaw is remotely reachable and carries a maximum CVSS 2.0 base score of 10.

10.0 CVSS 2.0 High EPSS 74% · top 0.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain topology/homeBaseView request. NOTE: some of these details are obtained from third party information.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityMaximum CVSS 2.0 score of 10 with network reachability, no authentication, and public exploit code plus very high EPSS probability make this an urgent fix despite the absence of KEV listing.

What it is

A stack-based buffer overflow exists in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51 and earlier. A long URI in an HTTP request handled by ovas.exe, such as a topology/homeBaseView request, overflows the buffer and can lead to remote code execution. The flaw is remotely reachable and carries a maximum CVSS 2.0 base score of 10.

Impact

An unauthenticated remote attacker can execute arbitrary code on the NNM server, typically with the privileges of the ovas.exe service. That gives full compromise of the management host, including confidentiality, integrity and availability impact.

Attack surface

Reached over the network via HTTP requests to the ovas.exe service on the NNM host; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The crafted URI is processed by ovwparser.dll during request parsing.

Exploitation

Public exploit code is referenced (Offensive Security and Exploit-DB entries), and EPSS shows a 30-day probability of 0.74345 at the 99.466th percentile, indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded there.

What to do

  • Apply the HP vendor patch for OV NNM 7.53/7.51 and earlier as referenced in the SecurityFocus and vendor advisories.
  • If patching is not immediately possible, restrict network access to the ovas.exe HTTP service to trusted management hosts only.
  • Place the NNM server behind a filtering proxy or WAF that rejects oversized or malformed URIs.
  • Monitor and log HTTP requests to ovas.exe for unusually long URI values.
  • Retire or isolate end-of-life NNM versions that no longer receive vendor fixes.

Detection

  • Inspect HTTP request logs for ovas.exe for abnormally long URI strings or topology/homeBaseView requests with oversized parameters.
  • Alert on crashes or restarts of ovas.exe or ovwparser.dll-related processes on NNM hosts.
  • Hunt for exploit payload patterns from the public Offensive Security and Exploit-DB PoCs in network traffic to the NNM service.
  • Monitor for unexpected child processes or outbound connections originating from the NNM server after HTTP requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1697 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2005-2773HP OpenView Network Node Manager command injection in multiple .ovpl scriptsHP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connec…KEVEPSS 75%analysed10.0CVE-2011-3167HP OpenView Network Node Manager remote code execution flawHP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code throug…EPSS 65%analysed10.0CVE-2011-3165Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-3166Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-0261Hp openview network node manager vulnerabilityUnspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute a…EPSS 16%10.0CVE-2011-0262Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows r…EPSS 17%10.0CVE-2011-0263Hp openview network node manager memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attacke…EPSS 17%10.0CVE-2011-0264Hp openview network node manager memory buffer overflow vulnerabilityStack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary cod…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2008-1697), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.