CVE-2014-6622: Infoleak
Published Nov 19, 2014
·Updated
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.
Affected Software
2 affected components
Arubanetworks Clearpass<=6.3.4
Arubanetworks Clearpass=6.4.0
Event History
Nov 19, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6622?
CVE-2014-6622 has a moderate severity rating due to its potential for remote exploitation by determining filename validity.
2
What versions of Aruba Networks ClearPass are affected by CVE-2014-6622?
CVE-2014-6622 affects Aruba Networks ClearPass versions prior to 6.3.6 and version 6.4.0.
3
How do I fix CVE-2014-6622?
To fix CVE-2014-6622, upgrade Aruba Networks ClearPass to version 6.3.6 or later, or to 6.4.1 or later.
4
What type of attack does CVE-2014-6622 allow?
CVE-2014-6622 allows remote attackers to confirm the validity of filenames.
5
Is CVE-2014-6622 a local or remote vulnerability?
CVE-2014-6622 is a remote vulnerability that can be exploited over the network.