VULNERABILITY INTELLIGENCE

CVE-2011-0271

CVSS score10 HIGH
EPSS probability7.33%
CISA KEVNot currently listed
Published2011-01-13
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Description

The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."

Weakness classification

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Primary references