SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-6030

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging…

HIGH 7.2EPSS 0.61%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.

CVSS 2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.61% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
hp/arcsight connector appliance · hp/arcsight logger · hp/arcsight command center · hp/arcsight connectors · hp/arcsight express · hp/arcsight management center · microfocus/arcsight enterprise security manager
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.