CVE-2020-7117

The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution. When the attacker is already authenticated to the administrative interface, they could then exploit the system, leading to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:36

Type Values Removed Values Added
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-005.txt - Vendor Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-005.txt - Vendor Advisory

Information

Published : 2020-06-03 13:15

Updated : 2024-11-21 05:36


NVD link : CVE-2020-7117

Mitre link : CVE-2020-7117

CVE.ORG link : CVE-2020-7117


JSON object : View

Products Affected

arubanetworks

  • clearpass_policy_manager