← Vulnerability feed

Vulnerability record · CVE-2011-3167 · published 2 November 2011

CVE-2011-3167: HP OpenView Network Node Manager remote code execution flaw

Hp · Openview Network Node Manager

HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1210. The record gives no root cause, no affected component and no technical detail beyond the version list, so defenders cannot reason about the exact mechanism from this data alone.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable code execution with full impact on a management platform, combined with a very high EPSS score, warrants urgent remediation despite the thin technical detail.

What it is

HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1210. The record gives no root cause, no affected component and no technical detail beyond the version list, so defenders cannot reason about the exact mechanism from this data alone.

Impact

Successful exploitation yields arbitrary code execution with full confidentiality, integrity and availability impact, meaning an attacker can take over the affected NNM process and host. Because the flaw is unauthenticated and network reachable, the exposure is complete compromise rather than data leakage.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, but the vector implies none.

Exploitation

The record is not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established here. EPSS is high at 0.664 (99.2nd percentile), indicating a strong statistical likelihood of exploitation activity.

What to do

  • Apply the HP vendor advisory patch for OV NNM 7.51 and 7.53, or upgrade to a supported release if one exists.
  • Restrict network access to NNM management interfaces to trusted administrative networks only.
  • Place NNM behind a firewall or jump host and block direct internet exposure of its listening ports.
  • Monitor vendor advisories for updated guidance since the root cause is unspecified and workarounds may not exist.
  • If the product is end-of-life and no patch is available, plan migration or decommissioning.

Detection

  • Monitor NNM process and host logs for unexpected child processes or command execution spawned by the NNM service.
  • Alert on anomalous inbound connections to NNM management ports from untrusted or external source addresses.
  • Baseline normal NNM network traffic and flag deviations in request patterns or payload sizes.
  • Watch for post-exploitation indicators such as new local accounts, web shells or outbound callbacks from the NNM host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-3167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2005-2773HP OpenView Network Node Manager command injection in multiple .ovpl scriptsHP OpenView Network Node Manager 6.2 through 7.50 passes user-supplied input into shell commands without sanitization in the node parameter of connec…KEVEPSS 75%analysed10.0CVE-2011-3165Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-3166Hp openview network node manager vulnerabilityUnspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown ve…EPSS 12%10.0CVE-2011-0261Hp openview network node manager vulnerabilityUnspecified vulnerability in jovgraph.exe in jovgraph in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute a…EPSS 16%10.0CVE-2011-0262Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in the stringToSeconds function in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows r…EPSS 17%10.0CVE-2011-0263Hp openview network node manager memory buffer overflow vulnerabilityMultiple stack-based buffer overflows in ovas.exe in the OVAS service in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote attacke…EPSS 17%10.0CVE-2011-0264Hp openview network node manager memory buffer overflow vulnerabilityStack-based buffer overflow in ovutil.dll in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary cod…EPSS 17%10.0CVE-2011-0265Hp openview network node manager memory buffer overflow vulnerabilityBuffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via …EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2011-3167), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.