First published: Thu Apr 16 2020(Updated: )
A vulnerability exists allowing attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack, a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Clearpass | >=6.7.0<6.7.13 | |
Arubanetworks Clearpass | >=6.8.0<6.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7114 is a vulnerability that allows attackers, when present in the same network segment as ClearPass' management interface, to make changes to certain databases in ClearPass by crafting HTTP packets.
The severity of CVE-2020-7114 is critical, with a severity value of 9.8.
Arubanetworks Clearpass versions between 6.7.0 and 6.7.13, as well as versions between 6.8.0 and 6.8.4, are affected by CVE-2020-7114.
CVE-2020-7114 has been fixed in version 6.7.13 and version 6.8.4 of Arubanetworks Clearpass.
The Common Weakness Enumeration (CWE) for CVE-2020-7114 is CWE-306.