Feeds

BOFHs beware OpenView, NetView flaw

Bug threatens network management mission control

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

A potentially devastating vulnerability involving components on the network management software of Hewlett-Packard and IBM's Tivoli division has come to light.

According to an alert published by CERT, systems running HP OpenView Network Node Manager (NNM) Version 6.1 and Tivoli NetView Versions 5.x and 6.x are vulnerable to a security flaw which could lead to an intruder gaining administrative control of a vulnerable machine.

If this is secured a user might change the configuration of a network or compromise other devices on a network.

Roy Hills, testing development director of security testing firm NTA Monitor, said the bug was "potentially very serious" because it might allow a hacker to control the "mission control" of a network, the network management console.

Hills said this station should be blocked by a firewall and should never be visible from the Internet, so the threat (though considerable) was one from internal attackers.

The root cause of the problem is a bug in ovactiond, an SNMP (Simple Network Management Protocol) trap and event handler software component used by both OpenView and NetView, which allows a hacker to execute arbitrary commands by sending a malicious message to the management server.

NTA Monitor's Hills said that such messages were sent in UDP packets, which are easier to forge than TCP packet, a factor which elevated the level of risk from the bug.

Versions of OpenView and NetView on both Unix and NT platforms might be vulnerable to attack, depending on how the software is configured. Patches to address the vulnerability have been issued by both vendors, more information on which is available here. ®

External Links

CERT Advisory: Vulnerability in OpenView and NetView

Related Stories

HP rejigs e-biz software
Cisco visits top clients to warn of SNMP bugs

Remote control for virtualized desktops

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.