CVE Vulnerabilities

CVE-2020-7113

Published: Apr 16, 2020 | Modified: Jul 21, 2021
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

Affected Software

Name Vendor Start Version End Version
Clearpass Arubanetworks 6.7.0 (including) 6.7.13 (excluding)
Clearpass Arubanetworks 6.8.0 (including) 6.8.4 (excluding)

References