CVE-2018-7058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/08/2018
Last modified:
18/10/2018

Description

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hp:aruba_clearpass_policy_manager:*:*:*:*:*:*:*:* 6.6.0 (including) 6.6.9 (excluding)


References to Advisories, Solutions, and Tools