First published: Fri Aug 29 2014(Updated: )
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba ClearPass Policy Manager | =6.3.0.60730 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.