CVE-2008-2438
UnknownEPSS 11.43%
Last modified
CVE-2008-2438 is a vulnerability of currently unknown severity. Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.. EPSS estimates a 11.43% chance of exploitation in the next 30 days.
Description
Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Openview Network Node Manager | 7.01 |
| Hp | Openview Network Node Manager | 7.51 |
| Hp | Openview Network Node Manager | 7.53 |
References
- http://secunia.com/secunia_research/2008-38/Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1187Vendor Advisory
- http://secunia.com/secunia_research/2008-38/Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1187Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2438?
Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.
How severe is CVE-2008-2438?
Severity scoring for CVE-2008-2438 is pending analysis. The EPSS model estimates a 11.43% probability of exploitation in the next 30 days.
How do I fix CVE-2008-2438?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2432Insecure method vulnerability in the GetFileList method in a…
- CVE-2008-2433The web management console in Trend Micro OfficeScan 7.0 thr…9.8
- CVE-2008-2434The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.…
- CVE-2008-2435Use-after-free vulnerability in the Trend Micro HouseCall Ac…
- CVE-2008-2436Multiple heap-based buffer overflows in the IppCreateServerR…
- CVE-2008-2437Stack-based buffer overflow in cgiRecvFile.exe in Trend Micr…
- CVE-2008-2439Directory traversal vulnerability in the UpdateAgent functio…
- CVE-2008-2441Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, …
- CVE-2008-2443SQL injection vulnerability in dpage.php in The Real Estate …
- CVE-2008-2444SQL injection vulnerability in userreg.php in CaLogic Calend…
- CVE-2008-2445Cross-site scripting (XSS) vulnerability in profile.php in W…
- CVE-2008-2446Multiple SQL injection vulnerabilities in Web Group Communic…
Are you affected by CVE-2008-2438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
