CVE-2017-9001
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Aruba ClearPass 6.6.3 and later includes a feature called "SSH Lockout", which causes ClearPass to lock accounts with too many login failures through SSH. When this feature is enabled, an unauthenticated remote command execution vulnerability is present which could allow an unauthenticated user to execute arbitrary commands on the underlying operating system with "root" privilege level. This vulnerability is only present when a specific feature has been enabled. The SSH Lockout feature is not enabled by default, so only systems which have enabled this feature are vulnerable.
Aruba ClearPass en versiones 6.6.3 y posteriores incluye una característica llamada "SSH Lockout", que provoca que ClearPass bloquee cuentas con demasiados errores de inicio de sesión mediante SSH. Cuando esta característica está habilitada, una vulnerabilidad de ejecución remota de comandos no autenticada está presente, lo que podría permitir que un usuario no autenticado ejecute comandos arbitrarios en el sistema operativo subyacente con el nivel de privilegios "root". Esta vulnerabilidad solo está presente cuando se habilita una característica en concreto. La característica SSH Lockout no está habilitada por defecto, por lo que solo los sistemas que tienen esta característica habilitada son vulnerables.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-05-15 CVE Reserved
- 2018-08-06 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-004.txt | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Aruba Clearpass Policy Manager Search vendor "Hp" for product "Aruba Clearpass Policy Manager" | >= 6.6.3 < 6.6.8 Search vendor "Hp" for product "Aruba Clearpass Policy Manager" and version " >= 6.6.3 < 6.6.8" | - |
Affected
|