First published: Wed Nov 19 2014(Updated: )
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which allows remote attackers to obtain version numbers, module configuration, and other sensitive information by reading the page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks ClearPass | <=6.3.4 | |
Aruba Networks ClearPass | =6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6621 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2014-6621, upgrade Aruba Networks ClearPass to version 6.3.6 or 6.4.1 or later.
Attackers can access version numbers, module configurations, and other sensitive system information through the vulnerability.
CVE-2014-6621 affects Aruba Networks ClearPass versions prior to 6.3.6 and version 6.4.0.
Yes, CVE-2014-6621 is exploitable remotely, allowing attackers to access the troubleshooting and diagnostics page.