CVE-2020-7114: Critical severity aruba networks clearpass vulnerability
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7114?
CVE-2020-7114 is a vulnerability that allows attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets.
What is the severity of CVE-2020-7114?
The severity of CVE-2020-7114 is critical, with a severity value of 9.8.
What software is affected by CVE-2020-7114?
Arubanetworks Clearpass versions between 6.7.0 and 6.7.13, as well as versions between 6.8.0 and 6.8.4, are affected by CVE-2020-7114.
How can this vulnerability be resolved?
CVE-2020-7114 has been fixed in version 6.7.13 and version 6.8.4 of Arubanetworks Clearpass.
What is the Common Weakness Enumeration (CWE) for CVE-2020-7114?
The Common Weakness Enumeration (CWE) for CVE-2020-7114 is CWE-306.