CVE Vulnerabilities

CVE-2020-7116

Published: Jun 03, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

Affected Software

Name Vendor Start Version End Version
Clearpass_policy_manager Arubanetworks 6.7.0 (including) 6.7.13 (including)
Clearpass_policy_manager Arubanetworks 6.8.0 (including) 6.8.6 (excluding)
Clearpass_policy_manager Arubanetworks 6.9.0 (including) 6.9.1 (excluding)

References