CVE-2008-3544
Last modified
CVE-2008-3544 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.. EPSS estimates a 18.04% chance of exploitation in the next 30 days.
Description
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Openview Network Node Manager | 7.01 |
| Hp | Openview Network Node Manager | 7.50 |
| Hp | Openview Network Node Manager | 7.51 |
| Hp | Openview Network Node Manager | 7.53 |
References
- http://secunia.com/advisories/31688Vendor Advisory
- http://secunia.com/advisories/31688Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3544?
How severe is CVE-2008-3544?
How do I fix CVE-2008-3544?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3537Unspecified vulnerability in ovalarmsrv in HP OpenView Netwo…
- CVE-2008-3538Unspecified vulnerability in HP Enterprise Discovery 2.0 thr…
- CVE-2008-3539Unspecified vulnerability in HP OpenView Select Identity (HP…
- CVE-2008-3541Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2008-3542Unspecified vulnerability in HP Insight Diagnostics before 7…
- CVE-2008-3543Unspecified vulnerability in NFS / ONCplus B.11.31_04 and ea…
- CVE-2008-3545Unspecified vulnerability in ovtopmd in HP OpenView Network …
- CVE-2008-3546Stack-based buffer overflow in the (1) diff_addremove and (2…
- CVE-2008-3547Buffer overflow in the server in OpenTTD 0.6.1 and earlier a…
- CVE-2008-3548Unspecified vulnerability in the Sun Netra T5220 Server with…
- CVE-2008-3549Unspecified vulnerability in the pthread_mutex_reltimedlock_…
- CVE-2008-3550The CQWeb login page in IBM Rational ClearQuest 7.0.1 allows…
Are you affected by CVE-2008-3544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
