CVE-2021-34616: OS Command Injection
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34616?
CVE-2021-34616 is classified as a high severity vulnerability due to its potential for remote arbitrary command execution.
How do I fix CVE-2021-34616?
To fix CVE-2021-34616, upgrade Aruba ClearPass Policy Manager to versions 6.10.0, 6.9.6, or 6.8.9 or later.
What versions of Aruba ClearPass Policy Manager are affected by CVE-2021-34616?
CVE-2021-34616 affects Aruba ClearPass Policy Manager versions prior to 6.10.0, 6.9.6, and 6.8.9.
Is CVE-2021-34616 exploitable remotely?
Yes, CVE-2021-34616 is a remote vulnerability, allowing attackers to execute commands from a remote location.
What should I do if I cannot update to the fixed versions for CVE-2021-34616?
If you cannot update, consider implementing additional security measures to limit exposure until the vulnerability is resolved.