CVE-2014-2593
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0056 (0.6%)
Percentile: 68.4%
EPSS: 2026-05-06
Affects
arubanetworks:clearpass_policy_managerTechnical description
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
Published: 8/29/2014, 1:55:04 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://osvdb.org/show/osvdb/109662
- http://www.arubanetworks.com/support/alerts/aid-050214.asc
- http://www.securityfocus.com/bid/69391
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95491
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2593
- http://osvdb.org/show/osvdb/109662
- http://www.arubanetworks.com/support/alerts/aid-050214.asc
- http://www.securityfocus.com/bid/69391