CVE-2016-4401: Critical severity aruba networks clearpass vulnerability
Published Nov 6, 2019
·Updated
Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
Affected Software
2 affected components
Arubanetworks Clearpass<6.5.7
Arubanetworks Clearpass>=6.6.0<6.6.2
Event History
Nov 6, 2019
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2016-4401.
2
What is the severity level of CVE-2016-4401?
The severity level of CVE-2016-4401 is critical (9.8).
3
Which software versions are affected by CVE-2016-4401?
Aruba ClearPass Policy Manager versions before 6.5.7 and 6.6.x before 6.6.2 are affected by CVE-2016-4401.
4
What can attackers do with CVE-2016-4401?
Attackers can obtain database credentials using CVE-2016-4401.
5
Is there a patch available for CVE-2016-4401?
Yes, you can find more information about the patch at the following link: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2016-010.txt