Vulnerability record · CVE-2010-2703 · published 28 July 2010
CVE-2010-2703: HP OpenView Network Node Manager Windows stack buffer overflow in ov.dll
Hp · Openview Network Node Manager
A stack-based buffer overflow exists in the execvp_nc function in the ov.dll module of HP OpenView Network Node Manager 7.51 and 7.53 on Windows. A long HTTP request to webappmon.exe can overwrite the stack and allow arbitrary code execution. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.
Description
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityMaximum CVSS v2 score of 10 with unauthenticated remote code execution, public exploit code and very high EPSS probability make this an urgent patching priority.
What it is
A stack-based buffer overflow exists in the execvp_nc function in the ov.dll module of HP OpenView Network Node Manager 7.51 and 7.53 on Windows. A long HTTP request to webappmon.exe can overwrite the stack and allow arbitrary code execution. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.
Impact
A remote attacker can execute arbitrary code with the privileges of the affected service, leading to full compromise of confidentiality, integrity and availability. No user interaction or prior authentication is required.
Attack surface
Reached over the network via HTTP requests to webappmon.exe, which invokes the vulnerable execvp_nc function in ov.dll. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are needed.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.71381 (99.38th percentile) and a public Exploit-DB entry (14916) exists, indicating mature public exploit code.
What to do
- Apply the HP vendor patch referenced in the bugtraq advisory (marc.info bugtraq 127973001009749) or upgrade to a fixed NNM release.
- If patching is not immediately possible, restrict network access to webappmon.exe and the NNM web interface to trusted management hosts only.
- Place the NNM server behind a reverse proxy or WAF that rejects oversized or malformed HTTP requests to webappmon.exe.
- Isolate the NNM Windows host on a segmented management VLAN with no direct internet exposure.
- Monitor vendor advisories for updated guidance since the product line is legacy and may no longer receive fixes.
Detection
- Inspect HTTP server and NNM web logs for unusually long request URIs or headers targeting webappmon.exe.
- Monitor for crashes or restarts of the NNM web process (ov.dll / webappmon.exe) that could indicate exploitation attempts.
- Use network IDS signatures for known Exploit-DB 14916 patterns against the NNM web interface.
- Alert on unexpected child processes or outbound connections originating from the NNM server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2703 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2703), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.