PatchSiren cyber security CVE debrief
CVE-2005-2773 Hewlett Packard (HP) CVE debrief
CVE-2005-2773 is a remote code execution issue affecting Hewlett Packard (HP) OpenView Network Node Manager. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, which means it should be treated as an active defensive priority for any environment that still uses the product.
- Vendor
- Hewlett Packard (HP)
- Product
- OpenView Network Node Manager
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Security teams, system administrators, and asset owners responsible for HP OpenView Network Node Manager, especially if any instances are legacy, broadly reachable, or difficult to patch quickly.
Technical summary
The supplied official records identify this issue as a remote code execution vulnerability in HP OpenView Network Node Manager and place it in CISA's Known Exploited Vulnerabilities catalog. The corpus does not provide affected version ranges, exploit mechanics, or a vendor advisory; the only remediation guidance included is CISA's note to apply updates per vendor instructions.
Defensive priority
Critical for any remaining deployments because it is a known-exploited remote code execution vulnerability.
Recommended defensive actions
- Apply vendor-recommended updates or mitigations immediately, per CISA KEV guidance.
- Inventory all HP OpenView Network Node Manager deployments, including legacy or forgotten instances.
- Prioritize internet-facing or broadly reachable management servers for remediation validation.
- If patching is unavailable or the product is end-of-life, isolate the system, restrict access, and plan replacement.
- Review recent logs and security alerts using your internal incident-response procedures for any signs of compromise.
Evidence notes
This debrief is based only on the supplied official CVE/NVD references and the CISA Known Exploited Vulnerabilities feed. The source corpus shows CISA added CVE-2005-2773 on 2022-03-25 with a due date of 2022-04-15 and the remediation note 'Apply updates per vendor instructions.' No affected-version matrix, exploit details, or vendor advisory text was provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2005-2773 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2005-2773
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2005-2773 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2005-2773
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.