CVE-2015-3655: CSRF
Published Aug 29, 2017
·Updated
Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to hijack the authentication of administrators by leveraging improper enforcement of the anti-CSRF token.
Affected Software
2 affected components
Arubanetworks Clearpass>=6.4.0<6.4.7
Arubanetworks Clearpass>=6.5.0<6.5.2
Event History
Aug 29, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3655?
CVE-2015-3655 has a high severity rating due to its potential for remote attackers to hijack administrator authentication.
2
How do I fix CVE-2015-3655?
To fix CVE-2015-3655, upgrade Aruba Networks ClearPass to version 6.4.7 or 6.5.2 or later.
3
What type of vulnerability is CVE-2015-3655?
CVE-2015-3655 is classified as a cross-site request forgery (CSRF) vulnerability.
4
What products are affected by CVE-2015-3655?
CVE-2015-3655 affects Aruba Networks ClearPass versions before 6.4.7 and versions in 6.5.0 to below 6.5.2.
5
Can CVE-2015-3655 be exploited remotely?
Yes, CVE-2015-3655 can be exploited remotely by attackers to hijack an admin's session.