First published: Mon Aug 06 2018(Updated: )
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks ClearPass | >=6.6.0<6.6.9 | |
Aruba Networks ClearPass | >=6.7.0<6.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7060 is a vulnerability in Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 that allows for CSRF attacks against authenticated users.
CVE-2018-7060 has a severity rating of 8.8, which is considered high.
Aruba ClearPass versions 6.6.0 to 6.6.9 and 6.7.0 to 6.7.1 are affected by CVE-2018-7060.
An attacker can exploit CVE-2018-7060 by manipulating an authenticated user into performing actions on the web administrative interface.
More information about CVE-2018-7060 can be found at the Aruba Networks Advisory website: [https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt)