{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-17T13:03:01.400","vulnerabilities":[{"cve":{"id":"CVE-2017-9001","sourceIdentifier":"security-alert@hpe.com","published":"2018-08-06T20:29:01.287","lastModified":"2024-11-21T03:35:08.760","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Aruba ClearPass 6.6.3 and later includes a feature called \"SSH Lockout\", which causes ClearPass to lock accounts with too many login failures through SSH. When this feature is enabled, an unauthenticated remote command execution vulnerability is present which could allow an unauthenticated user to execute arbitrary commands on the underlying operating system with \"root\" privilege level. This vulnerability is only present when a specific feature has been enabled. The SSH Lockout feature is not enabled by default, so only systems which have enabled this feature are vulnerable."},{"lang":"es","value":"Aruba ClearPass en versiones 6.6.3 y posteriores incluye una característica llamada \"SSH Lockout\", que provoca que ClearPass bloquee cuentas con demasiados errores de inicio de sesión mediante SSH. Cuando esta característica está habilitada, una vulnerabilidad de ejecución remota de comandos no autenticada está presente, lo que podría permitir que un usuario no autenticado ejecute comandos arbitrarios en el sistema operativo subyacente con el nivel de privilegios \"root\". Esta vulnerabilidad solo está presente cuando se habilita una característica en concreto. La característica SSH Lockout no está habilitada por defecto, por lo que solo los sistemas que tienen esta característica habilitada son vulnerables."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:aruba_clearpass_policy_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.3","versionEndExcluding":"6.6.8","matchCriteriaId":"47D951FA-4169-431B-B074-1F9DCA035B53"}]}]}],"references":[{"url":"https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-004.txt","source":"security-alert@hpe.com","tags":["Mitigation","Vendor Advisory"]},{"url":"https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2017-004.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"]}]}}]}