CVE-2018-7060

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
06/08/2018
Last modified:
10/10/2018

Description

Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:* 6.6.0 (including) 6.6.9 (excluding)
cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:* 6.7.0 (including) 6.7.1 (excluding)


References to Advisories, Solutions, and Tools