VendorsHPnetwork_automation9.10
Vulnerabilities

HP Network Automation 9.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2017-5814
A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published 2018-02-15 · Modified
10.0EPSS 0.087
CVE-2016-8511
A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x, v9.2x, v10.00, v10.00.01, v10.00.02, v10.10, v10.11, v10.11.01, v10.20 was found.
Published 2018-02-15 · Modified
9.8EPSS 0.153
CVE-2017-5810
A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published 2018-02-15 · Modified
9.8EPSS 0.047
CVE-2011-4790
Unspecified vulnerability in HP Network Automation 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to execute arbitrary code via unknown vectors.
Published 2012-02-02 · Modified
9.3EPSS 0.090
CVE-2017-5811
A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published 2018-02-15 · Modified
7.8EPSS 0.170
CVE-2017-5812
A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published 2018-02-15 · Modified
7.5EPSS 0.053
CVE-2016-4385
The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.
Published 2016-09-29 · Modified
7.5EPSS 0.044
CVE-2014-2646
Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.
Published 2014-10-10 · Modified
7.2EPSS 0.006
CVE-2017-5813
A remote unauthenticated access vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.
Published 2018-02-15 · Modified
6.8EPSS 0.019
CVE-2011-2403
SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Published 2011-08-01 · Modified
6.51 PoCEPSS 0.020
CVE-2011-1725
Unspecified vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to obtain sensitive information via unknown vectors.
Published 2011-04-27 · Modified
5.0EPSS 0.024
CVE-2011-2402
Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2011-08-01 · Modified
4.3EPSS 0.031