CVE-2016-4385

EUVD-2016-5385
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
hpnetwork_automation
9.10
hpnetwork_automation
9.20
hpnetwork_automation
9.22
hpnetwork_automation
9.22.01
hpnetwork_automation
9.22.02
hpnetwork_automation
10.00
hpnetwork_automation
10.00.01
hpnetwork_automation
10.00.02
hpnetwork_automation
10.10
hpnetwork_automation
10.11
𝑥
= Vulnerable software versions