CVE-2014-2593: Critical severity aruba clearpass policy manager vulnerability
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2593?
CVE-2014-2593 is rated as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2014-2593?
To fix CVE-2014-2593, it is recommended to update to a patched version of Aruba ClearPass Policy Manager that addresses this vulnerability.
Who is affected by CVE-2014-2593?
CVE-2014-2593 affects local users of Aruba Networks ClearPass Policy Manager version 6.3.0.60730.
What kind of attacks can exploit CVE-2014-2593?
CVE-2014-2593 can be exploited by local users to execute arbitrary commands using shell metacharacters.
What role do shell metacharacters play in CVE-2014-2593?
Shell metacharacters in CVE-2014-2593 allow attackers to manipulate command arguments, enabling them to run unauthorized commands.