First published: Fri Oct 15 2021(Updated: )
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has released patches for ClearPass Policy Manager that address this security vulnerability.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Clearpass Policy Manager | >=6.8.0<6.8.9 | |
Arubanetworks Clearpass Policy Manager | >=6.9.0<6.9.7 | |
Arubanetworks Clearpass Policy Manager | >=6.10.0<6.10.2 | |
Arubanetworks Clearpass Policy Manager | =6.8.9 | |
Arubanetworks Clearpass Policy Manager | =6.9.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40994 is a remote arbitrary command execution vulnerability in Aruba ClearPass Policy Manager.
The affected versions of Aruba ClearPass Policy Manager are ClearPass Policy Manager 6.10.x prior to 6.10.2, ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1, and ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1.
CVE-2021-40994 has a severity rating of 6.3, which is considered medium.
Aruba has released patches for the affected versions of ClearPass Policy Manager. It is recommended to apply the latest patches provided by Aruba.
You can find more information about CVE-2021-40994 on Aruba Networks' official website. Please refer to the reference link for detailed information.