TippingPoint Zero Day Initiative

(0Day) HP Operations Agent for NonStop Server HEALTH Packet Parsing Remote Code Execution Vulnerability

ZDI-12-165: August 22nd, 2012

CVSS Score

Affected Vendors

Affected Products

    Operations Agent for NonStop

Vulnerability Details

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Operations Agent for NonStop Server. User interaction is required to exploit this vulnerability in that the target must check the status of an existing node on the network.

The specific flaw exists within ELinkService process which listens on TCP ports 7771 and 8976 by default. The process performs insufficient bounds checking on user-supplied data within in a HEALTH packet prior to copying it into a fixed-length buffer on the stack. Remote, unauthenticated attackers can exploit this vulnerability by sending malformed message packets to the target, which could ultimately lead to arbitrary code execution under the context of the SYSTEM user.

Vendor Response

Hewlett-Packard states:

This vulnerability is being disclosed publicly without a patch in accordance with the ZDI 180 day deadline.

Disclosure Timeline

    2011-12-22 - Vulnerability reported to vendor
    2012-08-22 - Coordinated public release of advisory


This vulnerability was discovered by: