CVE-2014-2593: Arubanetworks Clearpass Policy Manager
High severity, CVSS 9.0. EPSS: 1.5% chance of exploitation in the next 30 days.
The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.
Affected products
- Arubanetworks Clearpass Policy Manager: version 6.3.0.60730 only
Published 2014-08-29. Last modified 2026-06-17.