PatchSiren

PatchSiren cyber security CVE debrief

CVE-2005-2773 Hewlett Packard (HP) CVE debrief

CVE-2005-2773 is a remote code execution issue affecting Hewlett Packard (HP) OpenView Network Node Manager. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, which means it should be treated as an active defensive priority for any environment that still uses the product.

Vendor
Hewlett Packard (HP)
Product
OpenView Network Node Manager
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-03-25
Original CVE updated
2022-03-25
Advisory published
2022-03-25
Advisory updated
2022-03-25

Who should care

Security teams, system administrators, and asset owners responsible for HP OpenView Network Node Manager, especially if any instances are legacy, broadly reachable, or difficult to patch quickly.

Technical summary

The supplied official records identify this issue as a remote code execution vulnerability in HP OpenView Network Node Manager and place it in CISA's Known Exploited Vulnerabilities catalog. The corpus does not provide affected version ranges, exploit mechanics, or a vendor advisory; the only remediation guidance included is CISA's note to apply updates per vendor instructions.

Defensive priority

Critical for any remaining deployments because it is a known-exploited remote code execution vulnerability.

Recommended defensive actions

  • Apply vendor-recommended updates or mitigations immediately, per CISA KEV guidance.
  • Inventory all HP OpenView Network Node Manager deployments, including legacy or forgotten instances.
  • Prioritize internet-facing or broadly reachable management servers for remediation validation.
  • If patching is unavailable or the product is end-of-life, isolate the system, restrict access, and plan replacement.
  • Review recent logs and security alerts using your internal incident-response procedures for any signs of compromise.

Evidence notes

This debrief is based only on the supplied official CVE/NVD references and the CISA Known Exploited Vulnerabilities feed. The source corpus shows CISA added CVE-2005-2773 on 2022-03-25 with a due date of 2022-04-15 and the remediation note 'Apply updates per vendor instructions.' No affected-version matrix, exploit details, or vendor advisory text was provided.

Official resources

This debrief is limited to the supplied official records and KEV data. It does not include vendor advisory details, affected-version information, or exploit mechanics because those were not present in the corpus.