PT-2018-17876 · Aruba · Aruba Clearpass

Publicado

2018-08-06

·

Atualizado

2018-10-18

·

CVE-2018-7058

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aruba ClearPass versions 6.6.x prior to 6.6.9
Description The issue allows an attacker to bypass authentication and gain administrator privileges on the system. It is exposed through ClearPass web interfaces, including administrative, guest captive portal, and API endpoints. The impact is lesser for customers who do not expose ClearPass web interfaces to untrusted users.
Recommendations For Aruba ClearPass versions 6.6.x prior to 6.6.9, update to version 6.6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the ClearPass web interfaces to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7058

Produtos afetados

Aruba Clearpass