CVE-2020-7115: Critical severity aruba clearpass policy manager vulnerability
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7115?
CVE-2020-7115 is a vulnerability in the ClearPass Policy Manager web interface that leads to authentication bypass and remote command execution.
What is the severity of CVE-2020-7115?
CVE-2020-7115 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2020-7115?
CVE-2020-7115 affects Arubanetworks Clearpass Policy Manager versions 6.7.0 to 6.7.13, versions 6.8.0 to 6.8.6, and versions 6.9.0 to 6.9.1.
How can I fix CVE-2020-7115?
CVE-2020-7115 can be fixed by upgrading to version 6.7.13-HF, 6.8.5-HF, or 6.9.2 of the ClearPass Policy Manager.
Where can I find more information about CVE-2020-7115?
More information about CVE-2020-7115 can be found at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/158368/ClearPass-Policy-Manager-Unauthenticated-Remote-Command-Execution.html) and [Aruba Networks](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-005.txt).