Vulnerability record · CVE-2013-6221 · published 18 June 2014
CVE-2013-6221: HP Service Virtualization CommunicationServlet path traversal enables remote code execution
Hp · Service Virtualization
HP Service Virtualization 3.x before 3.50.1 contains a directory traversal flaw in the CommunicationServlet, reachable when the AutoPass license server is enabled. An unauthenticated remote attacker can write arbitrary files, which can then be leveraged to execute arbitrary code. The issue is tracked as ZDI-CAN-2031 and has a public Metasploit module.
Description
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code and a very high EPSS probability make this an urgent patching priority.
What it is
HP Service Virtualization 3.x before 3.50.1 contains a directory traversal flaw in the CommunicationServlet, reachable when the AutoPass license server is enabled. An unauthenticated remote attacker can write arbitrary files, which can then be leveraged to execute arbitrary code. The issue is tracked as ZDI-CAN-2031 and has a public Metasploit module.
Impact
An attacker can create arbitrary files on the target host and escalate that to arbitrary code execution, giving full control of the affected system. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
The flaw is reached over the network via the CommunicationServlet HTTP interface, but only when the AutoPass license server component is enabled. No authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.77935, 99.5th percentile) and public exploit code exists in Exploit-DB, Packet Storm and the Metasploit framework, indicating active exploitation is feasible.
What to do
- Upgrade HP Service Virtualization to version 3.50.1 or later as directed by the vendor advisory.
- If the AutoPass license server is not required, disable it to remove the vulnerable attack surface.
- Restrict network access to the CommunicationServlet/AutoPass license server port to trusted hosts only.
- Monitor and, where possible, block traversal sequences (../) in HTTP requests to the servlet.
Detection
- Inspect HTTP request logs for path traversal patterns such as ../ or encoded variants targeting the CommunicationServlet or AutoPass license server.
- Alert on unexpected file creation or modification in web-accessible directories on hosts running HP Service Virtualization.
- Monitor for Metasploit module traffic or known exploit signatures associated with hp_autopass_license_traversal.
- Correlate outbound or lateral connections from the license server host following suspicious file writes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-6221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-6221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.