Lucene search

K
cve[email protected]CVE-2015-6030
HistoryNov 04, 2015 - 3:59 a.m.

CVE-2015-6030

2015-11-0403:59:08
CWE-264
web.nvd.nist.gov
32
cve-2015-6030
hp
arcsight logger
command center
connector appliance
privilege escalation
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.3%

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

Affected configurations

NVD
Node
hparcsight_connector_applianceRange6.4.0.6881.3
Node
hparcsight_loggerMatch6.0.0.7307.1
Node
hparcsight_command_centerMatch6.8.0.1896.0
Node
hparcsight_connectorsRange7.1.3
OR
hparcsight_expressMatch4.0
OR
hparcsight_expressMatch4.0p1
OR
hparcsight_management_centerRange2.0p1
OR
microfocusarcsight_enterprise_security_managerRange6.5

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.3%

Related for CVE-2015-6030