CVE-2015-3653: Critical severity aruba networks clearpass vulnerability
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain privileges by leveraging incorrect permission checking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3653?
CVE-2015-3653 is rated as a high severity vulnerability due to its potential to allow remote file writing and unauthorized privilege escalation.
How do I fix CVE-2015-3653?
To fix CVE-2015-3653, upgrade Aruba Networks ClearPass Policy Manager to version 6.4.7 or 6.5.2 or later.
What type of attack can CVE-2015-3653 allow?
CVE-2015-3653 can allow an attacker to perform denial of service attacks or gain elevated privileges through improper permission checks.
What software versions are affected by CVE-2015-3653?
CVE-2015-3653 affects Aruba Networks ClearPass versions up to 6.4.6 and the 6.5.x versions prior to 6.5.2.
Who can be affected by CVE-2015-3653?
Administrators with remote authenticated access to Aruba Networks ClearPass are at risk from CVE-2015-3653.