LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2005-2773: HP OpenView Network Node Manager Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2005-2773 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system.

CVE-2005-2773 is a remote code execution vulnerability in Hewlett Packard (HP) OpenView Network Node Manager. According to available summary information, the product could allow a remote attacker to execute arbitrary commands on the system. For IT and security teams that still run or discover legacy network-management infrastructure, this class of flaw matters because successful abuse can give an attacker a foothold on a host that often has broad visibility into the network.

Public detail on exact versions, attack vectors, and scoring is limited in the material provided here; treat the vendor advisory as the authoritative source for affected builds and fixed releases. The CISA-required action is to apply updates per vendor instructions. Known ransomware use is not documented for this CVE.

How it works

The weakness class is not specified in the provided facts beyond remote arbitrary command execution. In general terms for network-management products of this type, remote code execution flaws often arise when the application accepts untrusted input—via a management interface, protocol handler, or service endpoint—and passes it to an operating-system command interpreter or equivalent without adequate validation or sandboxing.

An attacker who can reach the vulnerable service would attempt to supply crafted input that causes the application to run attacker-chosen commands in the security context of the OpenView process. That context is frequently privileged enough to read configuration, alter monitoring data, or move laterally. Specific exploit mechanics, required authentication state, and precise request formats are not given in the facts; confirm those details only against the vendor advisory and do not rely on unverified proof-of-concept material.

Am I affected? How to find it in your systems

HP OpenView Network Node Manager is enterprise network- and systems-management software historically deployed on dedicated management servers, often in network operations centers or shared infrastructure segments. It may still appear in long-lived environments that have not fully migrated off older HP OpenView stacks.

If you cannot positively map a host to a patched build per the vendor, treat it as potentially affected until verified.

How to remediate

Patch first. Apply the updates specified by Hewlett Packard for OpenView Network Node Manager exactly as described in the vendor advisory and in line with the CISA direction to apply updates per vendor instructions. After patching, restart affected services as required and re-verify version strings and file hashes against the advisory.

If the advisory lists compensating configuration changes in addition to the patch, implement those as well and document the change.

If you can't patch immediately

When immediate patching is not possible, reduce exposure with layered compensating controls until the vendor update can be applied.

These steps do not replace the patch; they only buy time and lower likelihood of successful remote exploitation.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on management servers can lead to broader compromise and data exposure, even when ransomware use is not documented for the specific CVE. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate the host, preserve logs and memory as appropriate, credential-reset accounts that had access to the system, and assess what network or configuration data the attacker could have reached.

As a further check on personal or work email addresses that may have appeared in historical breaches, you can run a free exposure scan of your email against known breach data sets and then monitor or rotate credentials accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedHewlett Packard (HP) · OpenView Network Node Manager
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities