Last Modified: May 25, 2022
A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
Tweets last week: 0
Remaining steady
Yahoo results: 0
Remaining steady
Current EPSS Score: 0.00335
Remaining steady
Reddit Posts: 1
Remaining steady
Github Repos: 0
Remaining steady
Found exploits:
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: High
Availability: High
Base Score: 10.0
Exploitability Score:
3.9
Impact Score: 6.0
CVSS V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Access Vector: Network
Access Complexity: Low
Authentication: None
Confidentiality Impact: Complete
Integrity Impact: Complete
Availability Impact: Complete
Base Score: 10.0
Exploitability Score: 10.0
Impact Score: 10.0
CVSS V2: AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287
Condition | Configuration | |
---|---|---|
OR | ||
OR | ||
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:-:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks | |
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix1:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks | |
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix2:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks | |
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks | |
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks | |
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* Part: a Vendor: arubanetworks | Alle Schwachstellen für arubanetworks |
<?xml version="1.0" ?> <set operator="and"> <set operator="or"> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:-:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix1:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix2:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*"/> <prop key="application" value="cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*"/> </set> <prop key="program_influence" value="input"/> <prop key="range" value="remote"/> </set>
<?xml version="1.0" ?> <set operator="and"> <prop key="target" value="host"/> <set operator="or"> <prop key="program_influence" value="input"/> <prop key="program_influence" value="output"/> <prop key="program_influence" value="existence"/> </set> <prop key="data" value="any"/> <set operator="or"> <prop key="data_influence" value="read"/> <prop key="data_influence" value="write"/> <prop key="data_influence" value="delete"/> </set> <set operator="or"> <prop key="range" value="remote"/> <prop key="range" value="local"/> </set> </set>