CVE-2016-4385: HP Network Automation

High severity, CVSS 7.3. EPSS: 4.4% chance of exploitation in the next 30 days.

The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.

Affected products

  • HP Network Automation: version 9.10 only; version 9.20 only; version 9.22 only; version 9.22.01 only; version 9.22.02 only; version 10.00 only; …

Published 2016-09-29. Last modified 2026-06-17.