PT-2020-19382 · Aruba · Clearpass Policy Manager
Published
2020-06-03
·
Updated
2023-01-27
·
CVE-2020-7115
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ClearPass Policy Manager versions prior to 6.7.13-HF
ClearPass Policy Manager versions prior to 6.8.5-HF
ClearPass Policy Manager versions prior to 6.8.6
ClearPass Policy Manager versions prior to 6.9.1
Description
The ClearPass Policy Manager web interface has an issue that allows authentication bypass. After bypassing authentication, an attacker can execute a command that enables remote command execution in the underlying operating system.
Recommendations
For versions prior to 6.7.13-HF, update to 6.7.13-HF or higher.
For versions prior to 6.8.5-HF, update to 6.8.5-HF or higher.
For versions prior to 6.8.6, update to 6.8.6 or higher.
For versions prior to 6.9.1, update to 6.9.1 or higher.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearpass Policy Manager