← Vulnerability feed

Vulnerability record · CVE-2014-2624 · published 11 September 2014

CVE-2014-2624: HP Network Node Manager i remote code execution flaw

Hp · Network Node Manager I

HP Network Node Manager i (NNMi) versions 9.0x, 9.1x and 9.2x contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail beyond the CVSS vector, so the exact mechanism is unknown. It matters because NNMi is a network management platform, and code execution there can expose broad infrastructure visibility and control.

10.0 CVSS 2.0 High EPSS 65% · top 0.8%
10.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score is 10.0 with complete confidentiality, integrity and availability impact over the network without authentication, and EPSS is in the 99th percentile.

What it is

HP Network Node Manager i (NNMi) versions 9.0x, 9.1x and 9.2x contain an unspecified vulnerability that lets remote attackers execute arbitrary code. The record gives no root cause, affected component or attack vector detail beyond the CVSS vector, so the exact mechanism is unknown. It matters because NNMi is a network management platform, and code execution there can expose broad infrastructure visibility and control.

Impact

An attacker can run arbitrary code on the NNMi server, gaining the privileges of that service. Given the product's role, that access can be leveraged against managed network devices and data.

Attack surface

The CVSS 2.0 vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The specific interface or protocol is not stated in the record.

Exploitation

The CVE is not listed in CISA KEV and no reference carries an exploit tag, but EPSS is high at 0.65435 (99.2nd percentile), suggesting elevated likelihood of attempted exploitation. No public exploit details are provided in the record.

What to do

  • Apply the HP security bulletin fix referenced in the advisory (emr_na-c04378450) or upgrade NNMi to a supported, patched release.
  • Restrict network access to NNMi management interfaces to trusted administrative networks and hosts.
  • Place NNMi behind firewall rules and segmentation so it is not reachable from untrusted networks.
  • Monitor HP advisories for updated guidance since the vulnerability details are unspecified.
  • If patching is delayed, consider isolating the NNMi server and limiting its credentials and reach into managed devices.

Detection

  • Monitor NNMi server logs and host process activity for unexpected child processes or command execution spawned by the NNMi service.
  • Alert on anomalous inbound connections to NNMi management ports from untrusted source addresses.
  • Baseline normal NNMi network behavior and flag deviations such as new outbound connections to unusual destinations.
  • Review file integrity on NNMi application and configuration paths for unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-6218Hp network node manager i vulnerabilityUnspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vect…EPSS 8.7%10.0CVE-2012-3275Hp network node manager i vulnerabilityUnspecified vulnerability in HP Network Node Manager i (NNMi) 9.1x and 9.20 allows remote attackers to execute arbitrary code via unknown vectors.EPSS 10%9.8CVE-2017-8948Hp network node manager i vulnerabilityA Remote Bypass Security Restriction vulnerability in HPE Network Node Manager i (NNMi) Software versions v10.0x, v10.1x, v10.2x was found.EPSS 7.7%8.8CVE-2016-4398Hp network node manager i deserialization of untrusted data vulnerabilityA remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 1…EPSS 4.8%8.8CVE-2016-2009Hp network node manager i improper access control vulnerabilityHPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to execute arbitrary commands via a craf…EPSS 2.2%8.1CVE-2016-2014Hp network node manager i improper access control vulnerabilityHPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to modify data or cause a denial of serv…EPSS 2.1%7.8CVE-2016-4397Hp network node manager i code injection vulnerabilityA local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.EPSS 1.0%7.5CVE-2013-2351Hp network node manager i vulnerabilityUnspecified vulnerability in HP Network Node Manager i (NNMi) 9.00, 9.1x, and 9.2x allows remote attackers to obtain sensitive information, modify da…EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2014-2624), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.