CVE-2020-7110: XSS
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7110?
CVE-2020-7110 is a vulnerability in ClearPass that allows a malicious administrator to save and execute malicious scripts, leading to a privilege escalation attack.
Is Arubanetworks Clearpass affected by CVE-2020-7110?
Yes, Arubanetworks Clearpass versions between 6.7.0 and 6.7.13, as well as versions between 6.8.0 and 6.8.4, are affected by CVE-2020-7110.
What is the severity of CVE-2020-7110?
The severity of CVE-2020-7110 is medium, with a CVSS score of 4.8.
How can I fix CVE-2020-7110 vulnerability?
To fix CVE-2020-7110, you need to update ClearPass to version 6.7.13, 6.8.4, 6.9.0, or higher.
Where can I find more information about CVE-2020-7110?
You can find more information about CVE-2020-7110 at the following reference link: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-004.txt