CVE-2005-2773

CRITICAL KEV

HP OpenView Network Node Manager <7.50 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2005-2773 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 25, 2022. EIP tracks 3 public exploits from researchers including Metasploit, Lympex, including a Metasploit module exploits/unix/webapp/openview_connectednodes_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in HP OpenView's connectedNodes.ovpl CGI application by injecting arbitrary commands via the 'node' parameter. The payload is executed on the target system, and the output is captured and displayed.

Description

HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, and (4) ecscmg.ovpl.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/16887

This Metasploit module exploits a command injection vulnerability in HP OpenView's connectedNodes.ovpl CGI application by injecting arbitrary commands via the 'node' parameter. The payload is executed on the target system, and the output is captured and displayed.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HP OpenView connectedNodes.ovpl
No auth needed
Prerequisites: Network access to the target system · HP OpenView with vulnerable connectedNodes.ovpl CGI accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Lympex · cremotemultiple
https://www.exploit-db.com/exploits/1188

This exploit targets HP OpenView Network Node Manager (NNM) versions 6.2, 6.4, 7.01, and 7.50 by sending a crafted HTTP GET request to the '/OvCgi/connectedNodes.ovpl' endpoint with a command injection payload. The vulnerability allows remote command execution due to improper input validation in the 'node' parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HP OpenView Network Node Manager 6.2, 6.4, 7.01, 7.50
No auth needed
Prerequisites: Network access to the target system on port 3443
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/openview_connectednodes_exec.rb

This Metasploit module exploits a command injection vulnerability in HP OpenView's connectedNodes.ovpl CGI application by injecting arbitrary commands via the 'node' parameter. The payload is executed on the target system, and the output is captured and displayed.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: HP OpenView connectedNodes.ovpl (versions affected by CVE-2005-2773)
No auth needed
Prerequisites: Network access to the vulnerable CGI application · Target system running HP OpenView with the vulnerable component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Issue Tracking, Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112499121725662&w=2
Third Party Advisory vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21999
Broken Link vendor-advisory x_refsource_hp
http://www.securityfocus.com/advisories/9150
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14662
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16555/

Scores

CVSS v3 9.8
EPSS 0.8982
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2022-03-25
VulnCheck KEV 2020-12-01
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2005-2774
CWE
CWE-77
Status published
Products (1)
hp/openview_network_node_manager 6.2 - 7.50
Published Sep 02, 2005
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026