PT-2021-12641 · Aruba · Aruba Clearpass Policy Manager
Published
2021-02-23
·
Updated
2021-02-26
·
CVE-2020-7120
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Aruba ClearPass Policy Manager versions prior to 6.9.5
Aruba ClearPass Policy Manager version 6.8.8-HF1
Aruba ClearPass Policy Manager version 6.7.14-HF1
Description:
A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager. The vulnerability in ClearPass OnGuard could allow local authenticated users to cause a buffer overflow condition. A successful exploit could allow a local attacker to execute arbitrary code within the context the binary is running in, which is a lower privileged account.
Recommendations:
For versions prior to 6.9.5, update to version 6.9.5 or later.
For version 6.8.8-HF1, update to a version that includes the necessary security fixes.
For version 6.7.14-HF1, update to a version that includes the necessary security fixes.
As a temporary workaround, consider restricting access to the ClearPass OnGuard module to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aruba Clearpass Policy Manager