Vulnerability record · CVE-2011-3167 · published 2 November 2011
CVE-2011-3167: HP OpenView Network Node Manager remote code execution flaw
Hp · Openview Network Node Manager
HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1210. The record gives no root cause, no affected component and no technical detail beyond the version list, so defenders cannot reason about the exact mechanism from this data alone.
Description
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1210.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable code execution with full impact on a management platform, combined with a very high EPSS score, warrants urgent remediation despite the thin technical detail.
What it is
HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 contain an unspecified vulnerability that lets remote attackers execute arbitrary code through unknown vectors, tracked as ZDI-CAN-1210. The record gives no root cause, no affected component and no technical detail beyond the version list, so defenders cannot reason about the exact mechanism from this data alone.
Impact
Successful exploitation yields arbitrary code execution with full confidentiality, integrity and availability impact, meaning an attacker can take over the affected NNM process and host. Because the flaw is unauthenticated and network reachable, the exposure is complete compromise rather than data leakage.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether user interaction is required, but the vector implies none.
Exploitation
The record is not listed in CISA KEV and no reference carries an exploit tag, so confirmed in-the-wild exploitation is not established here. EPSS is high at 0.664 (99.2nd percentile), indicating a strong statistical likelihood of exploitation activity.
What to do
- Apply the HP vendor advisory patch for OV NNM 7.51 and 7.53, or upgrade to a supported release if one exists.
- Restrict network access to NNM management interfaces to trusted administrative networks only.
- Place NNM behind a firewall or jump host and block direct internet exposure of its listening ports.
- Monitor vendor advisories for updated guidance since the root cause is unspecified and workarounds may not exist.
- If the product is end-of-life and no patch is available, plan migration or decommissioning.
Detection
- Monitor NNM process and host logs for unexpected child processes or command execution spawned by the NNM service.
- Alert on anomalous inbound connections to NNM management ports from untrusted or external source addresses.
- Baseline normal NNM network traffic and flag deviations in request patterns or payload sizes.
- Watch for post-exploitation indicators such as new local accounts, web shells or outbound callbacks from the NNM host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3167 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3167), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.