CVE-2015-4650
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2015-009.txt
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| arubanetworks | clearpass_policy_manager | {"endIncluding":"6.4.6"} | |
| arubanetworks | clearpass_policy_manager | 6.5.0 | |
| arubanetworks | clearpass_policy_manager | 6.5.1 | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.