PT-2020-19381 · Aruba · Clearpass

Published

2020-04-16

·

Updated

2020-04-23

·

CVE-2020-7114

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClearPass versions prior to 6.7.13 ClearPass versions prior to 6.8.4 ClearPass versions prior to 6.9.0
Description A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur.
Recommendations For versions prior to 6.7.13, update to version 6.7.13 or higher. For versions prior to 6.8.4, update to version 6.8.4 or higher. For versions prior to 6.9.0, update to version 6.9.0 or higher.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7114

Affected Products

Clearpass