CVE-2015-3653

HIGH

Aruba Networks ClearPass Policy Manager <6.4.7, <6.5.2 - Privilege ...

Title source: llm
STIX 2.1

Description

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain privileges by leveraging incorrect permission checking.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100593

Scores

CVSS v3 7.2
EPSS 0.0065
EPSS Percentile 71.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (3)
arubanetworks/clearpass 6.5
arubanetworks/clearpass 6.5.1
arubanetworks/clearpass < 6.4.6
Published Aug 29, 2017
Tracked Since Feb 18, 2026