CVE-2015-3656
HIGHAruba Networks ClearPass Policy Manager <6.4.7, <6.5.2 - Privilege ...
Title source: llmDescription
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100597
Vendor Advisory x_refsource_confirm
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2015-009.txt
Scores
CVSS v3
7.2
EPSS
0.0076
EPSS Percentile
73.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-285
Status
published
Products (3)
arubanetworks/clearpass
6.5
arubanetworks/clearpass
6.5.1
arubanetworks/clearpass
< 6.4.6
Published
Aug 29, 2017
Tracked Since
Feb 18, 2026