CVE-2016-4385
HIGHHP Network Automation Software - RCE
Title source: llmDescription
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
References (4)
Scores
CVSS v3
7.3
EPSS
0.0367
EPSS Percentile
87.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Classification
CWE
CWE-502
Status
draft
Affected Products (10)
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
hp/network_automation
Timeline
Published
Sep 29, 2016
Tracked Since
Feb 18, 2026