CVE-2009-3849
HP Openview Network Node Manager - Memory Corruption
Title source: ruleDescription
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template parameter to nnmRptConfig.exe, related to the strcat function; or (2) a long Oid parameter to snmp.exe.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotecgi
https://www.exploit-db.com/exploits/16780
metasploit
WORKING POC
GREAT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/hp_nnm_snmp.rb
References (11)
Scores
EPSS
0.8337
EPSS Percentile
99.3%
Details
CWE
CWE-119
Status
published
Products (3)
hp/openview_network_node_manager
7.0.1 (4 CPE variants)
hp/openview_network_node_manager
7.51 (4 CPE variants)
hp/openview_network_node_manager
7.53 (4 CPE variants)
Published
Dec 10, 2009
Tracked Since
Feb 18, 2026