PT-2018-17882 · Aruba · Aruba Clearpass Policy Manager

Published

2018-12-07

·

Updated

2019-02-05

·

CVE-2018-7067

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aruba ClearPass Policy Manager versions prior to 6.7.6 Aruba ClearPass Policy Manager versions prior to 6.6.10-hotfix
Description A remote authentication bypass issue in Aruba ClearPass Policy Manager can lead to the complete compromise of a cluster. This is due to an authentication flaw that can be exploited through a specially crafted API call, requiring network access to the administrative web interface.
Recommendations For versions prior to 6.7.6, update to version 6.7.6 to resolve the issue. For versions prior to 6.6.10-hotfix, apply the 6.6.10-hotfix to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7067

Affected Products

Aruba Clearpass Policy Manager