← Vulnerability feed

Vulnerability record · CVE-2010-2703 · published 28 July 2010

CVE-2010-2703: HP OpenView Network Node Manager Windows stack buffer overflow in ov.dll

Hp · Openview Network Node Manager

A stack-based buffer overflow exists in the execvp_nc function in the ov.dll module of HP OpenView Network Node Manager 7.51 and 7.53 on Windows. A long HTTP request to webappmon.exe can overwrite the stack and allow arbitrary code execution. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.

10.0 CVSS 2.0 High EPSS 71% · top 0.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityMaximum CVSS v2 score of 10 with unauthenticated remote code execution, public exploit code and very high EPSS probability make this an urgent patching priority.

What it is

A stack-based buffer overflow exists in the execvp_nc function in the ov.dll module of HP OpenView Network Node Manager 7.51 and 7.53 on Windows. A long HTTP request to webappmon.exe can overwrite the stack and allow arbitrary code execution. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.

Impact

A remote attacker can execute arbitrary code with the privileges of the affected service, leading to full compromise of confidentiality, integrity and availability. No user interaction or prior authentication is required.

Attack surface

Reached over the network via HTTP requests to webappmon.exe, which invokes the vulnerable execvp_nc function in ov.dll. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.71381 (99.38th percentile) and a public Exploit-DB entry (14916) exists, indicating mature public exploit code.

What to do

  • Apply the HP vendor patch referenced in the bugtraq advisory (marc.info bugtraq 127973001009749) or upgrade to a fixed NNM release.
  • If patching is not immediately possible, restrict network access to webappmon.exe and the NNM web interface to trusted management hosts only.
  • Place the NNM server behind a reverse proxy or WAF that rejects oversized or malformed HTTP requests to webappmon.exe.
  • Isolate the NNM Windows host on a segmented management VLAN with no direct internet exposure.
  • Monitor vendor advisories for updated guidance since the product line is legacy and may no longer receive fixes.

Detection

  • Inspect HTTP server and NNM web logs for unusually long request URIs or headers targeting webappmon.exe.
  • Monitor for crashes or restarts of the NNM web process (ov.dll / webappmon.exe) that could indicate exploitation attempts.
  • Use network IDS signatures for known Exploit-DB 14916 patterns against the NNM web interface.
  • Alert on unexpected child processes or outbound connections originating from the NNM server host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-2703 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2005-2773HP OpenView Network Node Manager command injection in multiple .ovpl scriptsHP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connec…KEVEPSS 75%analysed10.0CVE-2011-3167HP OpenView Network Node Manager remote code execution flawHP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code throug…EPSS 65%analysed10.0CVE-2011-3165Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-3166Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-0261Hp openview network node manager vulnerabilityUnspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute a…EPSS 16%10.0CVE-2011-0262Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows r…EPSS 17%10.0CVE-2011-0263Hp openview network node manager memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attacke…EPSS 17%10.0CVE-2011-0264Hp openview network node manager memory buffer overflow vulnerabilityStack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary cod…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2010-2703), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.