CVE-2014-6626
 
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.
Aruba Networks ClearPass anterior a 6.3.6 y 6.4.x anterior a 6.4.1 no restringe correctamente el acceso a funciones administrativas sin especificar, lo que permite a atacantes remotos evadir la autenticación y ejecutar acciones administrativas a través de vectores desconocidos
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-09-19 CVE Reserved
- 2014-11-19 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/61916 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.arubanetworks.com/support/alerts/aid-10282014.txt | 2014-11-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Clearpass Search vendor "Arubanetworks" for product "Clearpass" | <= 6.3.4 Search vendor "Arubanetworks" for product "Clearpass" and version " <= 6.3.4" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Search vendor "Arubanetworks" for product "Clearpass" | 6.4.0 Search vendor "Arubanetworks" for product "Clearpass" and version "6.4.0" | - |
Affected
|