CVE Vulnerabilities

CVE-2020-7116

Published: Jun 03, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

Affected Software

NameVendorStart VersionEnd Version
Clearpass_policy_managerArubanetworks6.7.0 (including)6.7.13 (including)
Clearpass_policy_managerArubanetworks6.8.0 (including)6.8.6 (excluding)
Clearpass_policy_managerArubanetworks6.9.0 (including)6.9.1 (excluding)

References