First published: Tue Feb 23 2021(Updated: )
A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim’s browser in the context of the affected interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba ClearPass Policy Manager | <6.7.14 | |
Aruba ClearPass Policy Manager | >=6.8.0<6.8.6 | |
Aruba ClearPass Policy Manager | >=6.9.0<6.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26678 is a high severity vulnerability due to its ability to allow remote unauthenticated stored cross-site scripting attacks.
To fix CVE-2021-26678, update Aruba ClearPass Policy Manager to version 6.9.5 or later, or to versions 6.8.8-HF1 or 6.7.14-HF1.
CVE-2021-26678 affects users of Aruba ClearPass Policy Manager versions prior to 6.9.5, 6.8.8-HF1, and 6.7.14-HF1.
CVE-2021-26678 exploits a vulnerability in the web-based management interface of Aruba ClearPass that enables stored cross-site scripting.
Yes, CVE-2021-26678 can be exploited by unauthenticated remote attackers.