CVE-2020-7117: Critical severity Arubanetworks Clearpass Policy Manager vulnerability
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7117?
CVE-2020-7117 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2020-7117?
To fix CVE-2020-7117, update your Aruba ClearPass Policy Manager to the latest patched version beyond 6.9.0.
What systems are affected by CVE-2020-7117?
CVE-2020-7117 affects Aruba ClearPass Policy Manager versions between 6.7.0 and 6.9.0, including early releases of versions 6.8.0 and 6.9.0.
What are the risks associated with CVE-2020-7117?
The risks associated with CVE-2020-7117 include unauthorized remote command execution by an authenticated attacker.
Is there a workaround for CVE-2020-7117?
Currently, the recommended solution for CVE-2020-7117 is to update to the latest version, as no effective workaround exists.