Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against HP OpenView Network Node Manager Denial of Service

Subscribe

Check Point Reference: CPAI-2009-302
Date Published:
Severity:
Source: Secunia Advisory: SA37376
Industry Reference(s): CVE-2009-3840
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
HP OpenView Network Node Manager 7.51
HP OpenView Network Node Manager 7.53
Vulnerability Description
A denial of service vulnerability exists in HP OpenView Network Node Manager. The flaw is due to a design weakness when processing crafted packets sent to the server. Remote attackers could exploit this vulnerability by sending a malicious request to the affected TCP port. Successful exploitation can lead to a denial of service condition of the target system.
Update/Patch Available
The vendor, HP, has released an advisory addressing this vulnerability:
Hp Support
Vulnerability Details
The vulnerability is caused due to an error in the database service (ovdbrun.exe) when processing TCP packets. This can be exploited to terminate the service via a specially crafted packet containing an invalid error code.

Protection Overview
By enabling this protection, IPS-1 will detect and block malformed packets sent to HP OpenView's ovdbrun.exe process.

In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 NGX R65 & IPS-1

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Enterprise Software, and select the HP OpenView Network Node Manager protection group.
3. Click HP OpenView Network Node Manager SolidDB Denial of Service (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: HP OpenView Network Node Manager
Description: HP OpenView Network Node Manager SolidDB Denial of Service