CVE-2015-6030
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- hp/arcsight connector appliance · hp/arcsight logger · hp/arcsight command center · hp/arcsight connectors · hp/arcsight express · hp/arcsight management center · microfocus/arcsight enterprise security manager
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04872416Third Party Advisory
- http://www.kb.cert.org/vuls/id/842252Third Party Advisory, US Government Resource
- http://www.securitytracker.com/id/1034072Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034073Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04872416Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.