Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:HPOV:OVTOPMD-DOS

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

HP OpenView Network Node Manager 'ovtopmd' Denial of Service

Release Date

2012/11/12

Update Number

2202

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

APP: HP OpenView Network Node Manager 'ovtopmd' Denial of Service


This signature detects attempts to exploit a known flaw in HP OpenView Network Node Manager, which is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' and 'ovtopmd.exe' processes. A sucessful exploit could result in a Denial of Service (DoS).

Extended Description

HP OpenView Network Node Manager is prone to multiple vulnerabilities affecting the 'ovalarmsrv.exe' and 'ovtopmd.exe' processes. These issues include a directory-traversal issue and multiple denial-of-service issues. UPDATE (April 14, 2008): Secunia Research discovered, independently, that the 'OpenView5.exe' process is also prone to the directory-traversal issue; this affects Network Node Manager 7.51. Note that 'ovalarmsrv.exe' may also be named 'OpenView5.exe'. Attackers can exploit these issues to access potentially sensitive data on the affected computer or to deny service to legitimate users. HP OpenView Network Node Manager 7.53 is vulnerable; other versions may also be affected.

Affected Products

  • Hp openview_network_node_manager 7.01
  • Hp openview_network_node_manager 7.51
  • Hp openview_network_node_manager 7.53
  • Nortel_networks ensm-enterprise_nms 10.4
  • Nortel_networks ensm-enterprise_nms 10.5
  • Nortel_networks enterprise_network_management_system
  • Nortel_networks multiservice_data_manager
  • Nortel_networks multiservice_switch-mdm

References

  • BugTraq: 28745
  • CVE: CVE-2008-0068

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out