PT-2018-8488 · Aruba · Aruba Clearpass
Publicado
2018-08-06
·
Atualizado
2019-10-03
·
CVE-2017-9001
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Aruba ClearPass versions 6.6.3 and later
Description
The issue is related to the "SSH Lockout" feature, which when enabled, introduces an unauthenticated remote command execution issue. This could allow an unauthenticated user to execute arbitrary commands on the underlying operating system with "root" privilege level. The feature is not enabled by default, so only systems with this feature enabled are affected.
Recommendations
For Aruba ClearPass versions 6.6.3 and later with the SSH Lockout feature enabled, consider disabling the SSH Lockout feature until a patch is available. Restrict access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aruba Clearpass