CVE Vulnerabilities

CVE-2016-4401

Insufficiently Protected Credentials

Published: Nov 06, 2019 | Modified: Nov 08, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Clearpass Arubanetworks * 6.5.7 (excluding)
Clearpass Arubanetworks 6.6.0 (including) 6.6.2 (excluding)

Potential Mitigations

References