CVE-2015-6030: High severity hp arcsight connector appliance firmware vulnerability
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6030?
CVE-2015-6030 is considered a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2015-6030?
To fix CVE-2015-6030, ensure you update to the latest versions of affected HP ArcSight products that address this vulnerability.
What systems are impacted by CVE-2015-6030?
CVE-2015-6030 affects HP ArcSight Logger version 6.0.0.7307.1, ArcSight Command Center version 6.8.0.1896.0, and various versions of ArcSight Connector Appliances.
What kind of attack does CVE-2015-6030 enable?
CVE-2015-6030 enables local users to gain elevated privileges by exploiting the misuse of the arcsight account.
Is there a workaround for CVE-2015-6030?
Currently, the best approach is to update the software as there are no documented effective workarounds for CVE-2015-6030.