CVE-2010-2709 describes a critical stack-based buffer overflow in webappmon.exe within HP OpenView Network Node Manager (OV NNM) versions 7.51 and 7.53. This vulnerability allows unauthenticated remote attackers to execute arbitrary code by sending a crafted cookie containing an overly long OvJavaLocale value. With a CVSS score of 9.3, it represents a severe risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit modules exist in Metasploit and ExploitDB, indicating readily available exploitation tools, despite a lack of significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.51CPE matchmatch criteria | cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:* | ||
7.51CPE matchmatch criteria | cpe:2.3:a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.