CVE-2014-2593Clearpass Policy Manager vulnerability

CWE-2643 documents3 sources
Severity
9.0CRITICALNVD
EPSS
0.6%
top 31.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateMay 17

Description

The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-797g-c7cw-4p6g: The management console in Aruba Networks ClearPass Policy Manager 62022-05-17
CVEList
CVE-2014-2593: The management console in Aruba Networks ClearPass Policy Manager 62014-08-29
CVE-2014-2593 — Clearpass Policy Manager vulnerability | cvebase