PT-2021-17087 · Aruba · Aruba Clearpass Policy Manager

Published

2021-02-23

·

Updated

2021-02-26

·

CVE-2021-26682

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Aruba ClearPass Policy Manager versions prior to 6.9.5 Aruba ClearPass Policy Manager version 6.8.8-HF1 Aruba ClearPass Policy Manager version 6.7.14-HF1
Description A remote reflected cross-site scripting (XSS) vulnerability was discovered in the guest portal interface of Aruba ClearPass Policy Manager. This vulnerability could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the portal. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the guest portal interface.
Recommendations For versions prior to 6.9.5, update to version 6.9.5 or later. For version 6.8.8-HF1, update to a version that includes the fix for this issue. For version 6.7.14-HF1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the guest portal interface until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-26682

Affected Products

Aruba Clearpass Policy Manager