Vulnerability record · CVE-2010-1552 · published 13 May 2010
CVE-2010-1552: HP OpenView NNM snmpviewer.exe stack buffer overflow
Hp · Openview Network Node Manager
A stack-based buffer overflow exists in the doLoad function of snmpviewer.exe in HP OpenView Network Node Manager 7.01, 7.51 and 7.53. The act and app parameters are copied without bounds checking, so a remote attacker can overwrite the stack and execute arbitrary code. Because the affected component is remotely reachable and no credentials are required, this is a serious pre-authentication risk to exposed NNM installations.
Description
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote, unauthenticated code execution with complete impact and a very high EPSS score makes this a top remediation priority despite the absence of KEV listing.
What it is
A stack-based buffer overflow exists in the doLoad function of snmpviewer.exe in HP OpenView Network Node Manager 7.01, 7.51 and 7.53. The act and app parameters are copied without bounds checking, so a remote attacker can overwrite the stack and execute arbitrary code. Because the affected component is remotely reachable and no credentials are required, this is a serious pre-authentication risk to exposed NNM installations.
Impact
An attacker gains remote code execution in the context of the snmpviewer.exe process, which can lead to full compromise of the NNM host. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
Reached over the network via the snmpviewer.exe interface, with the malicious act and app parameters supplied by the attacker. The AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is 0.67088 (99.3rd percentile), indicating a high modeled likelihood of exploitation. Reference tags are empty, so no public exploit or PoC status can be confirmed from this record.
What to do
- Apply the HP patch for the affected OpenView NNM versions (7.01, 7.51, 7.53) as the first action.
- Restrict network access to the snmpviewer.exe service to trusted management hosts only.
- Segment or firewall NNM management interfaces away from untrusted networks.
- Monitor vendor advisories for updated fixes if the installed version is no longer supported.
Detection
- Inspect NNM or web/proxy logs for requests to snmpviewer.exe with unusually long act or app parameter values.
- Alert on process crashes or restarts of snmpviewer.exe on NNM hosts.
- Hunt for unexpected child processes or command shells spawned by snmpviewer.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1552), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.