CVE-2018-7060: CSRF
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7060?
CVE-2018-7060 is a vulnerability in Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 that allows for CSRF attacks against authenticated users.
How severe is CVE-2018-7060?
CVE-2018-7060 has a severity rating of 8.8, which is considered high.
Which software versions are affected by CVE-2018-7060?
Aruba ClearPass versions 6.6.0 to 6.6.9 and 6.7.0 to 6.7.1 are affected by CVE-2018-7060.
How can an attacker exploit CVE-2018-7060?
An attacker can exploit CVE-2018-7060 by manipulating an authenticated user into performing actions on the web administrative interface.
Where can I find more information about CVE-2018-7060?
More information about CVE-2018-7060 can be found at the Aruba Networks Advisory website: [https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt)