Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.
References
Link | Resource |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt | Vendor Advisory |
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt - Vendor Advisory |
Information
Published : 2018-08-06 20:29
Updated : 2024-11-21 04:11
NVD link : CVE-2018-7060
Mitre link : CVE-2018-7060
CVE.ORG link : CVE-2018-7060
JSON object : View
Products Affected
arubanetworks
- clearpass
CWE
CWE-352
Cross-Site Request Forgery (CSRF)