Check Point Reference: | CPAI-2014-1855 |
Date Published: | 14 Oct 2014 |
Severity: | Critical |
Last Updated: | Tuesday 14 October, 2014 |
Source: | HP |
Industry Reference: | CVE-2014-2624 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | HP Network Node Manager i (NNMi) 9.0x HP Network Node Manager i (NNMi) 9.1x HP Network Node Manager i (NNMi) 9.2x |
Vulnerability Description | Multiple buffer overflow vulnerabilities exist in HP Network Node Manager I (NNMi). These vulnerabilities are caused by copying user supplied data into stack-based buffers without sufficient validation in ovopi.dll. By sending a crafted request to the vulnerable product on port 696/UDP, a remote unauthenticated attacker could exploit these vulnerabilities to execute arbitrary code with system privileges. |
SmartView Tracker will log the following entries:
Attack Name: HP Products Protection Violation.
Attack Information: HP Network Node Manager I ovopi.dll Buffer Overflow