← Vulnerability feed

Vulnerability record · CVE-2013-6221 · published 18 June 2014

CVE-2013-6221: HP Service Virtualization CommunicationServlet path traversal enables remote code execution

Hp · Service Virtualization

HP Service Virtualization 3.x before 3.50.1 contains a directory traversal flaw in the CommunicationServlet, reachable when the AutoPass license server is enabled. An unauthenticated remote attacker can write arbitrary files, which can then be leveraged to execute arbitrary code. The issue is tracked as ZDI-CAN-2031 and has a public Metasploit module.

10.0 CVSS 2.0 High EPSS 78% · top 0.4% CWE-22 · Path traversal
10.0CVSS 2.0 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, public exploit code and a very high EPSS probability make this an urgent patching priority.

What it is

HP Service Virtualization 3.x before 3.50.1 contains a directory traversal flaw in the CommunicationServlet, reachable when the AutoPass license server is enabled. An unauthenticated remote attacker can write arbitrary files, which can then be leveraged to execute arbitrary code. The issue is tracked as ZDI-CAN-2031 and has a public Metasploit module.

Impact

An attacker can create arbitrary files on the target host and escalate that to arbitrary code execution, giving full control of the affected system. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

The flaw is reached over the network via the CommunicationServlet HTTP interface, but only when the AutoPass license server component is enabled. No authentication or user interaction is required per the AV:N/AC:L/Au:N vector.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.77935, 99.5th percentile) and public exploit code exists in Exploit-DB, Packet Storm and the Metasploit framework, indicating active exploitation is feasible.

What to do

  • Upgrade HP Service Virtualization to version 3.50.1 or later as directed by the vendor advisory.
  • If the AutoPass license server is not required, disable it to remove the vulnerable attack surface.
  • Restrict network access to the CommunicationServlet/AutoPass license server port to trusted hosts only.
  • Monitor and, where possible, block traversal sequences (../) in HTTP requests to the servlet.

Detection

  • Inspect HTTP request logs for path traversal patterns such as ../ or encoded variants targeting the CommunicationServlet or AutoPass license server.
  • Alert on unexpected file creation or modification in web-accessible directories on hosts running HP Service Virtualization.
  • Monitor for Metasploit module traffic or known exploit signatures associated with hp_autopass_license_traversal.
  • Correlate outbound or lateral connections from the license server host following suspicious file writes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-6221 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed6.5CVE-2026-20262Cisco Catalyst SD-WAN Manager path traversal in file uploadCisco Catalyst SD-WAN Manager (formerly vManage) fails to properly validate user-supplied input during a file upload process, allowing path traversal…KEVEPSS 28%analysed8.4CVE-2024-1708ConnectWise ScreenConnect path traversal enabling remote code executionConnectWise ScreenConnect 23.9.7 and earlier contain a path-traversal flaw (CWE-22) that can let an attacker execute remote code or reach confidentia…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2013-6221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.