Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2593

Опубликовано: 29 авг. 2014
Источник: nvd
CVSS2: 9
EPSS Низкий

Описание

The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.

Комментарий

Per: http://osvdb.org/show/osvdb/109662

"Aruba Networks ClearPass Policy Manager contains a flaw in the Management console. The issue is triggered when parsing commands. With a specially crafted command, an authenticated remote attacker can execute arbitrary commands with root privileges."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.3.0.60730:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00563
Низкий

9 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.

EPSS

Процентиль: 68%
0.00563
Низкий

9 Critical

CVSS2

Дефекты

CWE-264