vendor:
ClearPass Policy Manager
by:
SpicyItalian
9.8
CVSS
CRITICAL
Unauthenticated Remote Command Execution
78
CWE
Product Name: ClearPass Policy Manager
Affected Version From: ClearPass 6.7.x prior to 6.7.13-HF, ClearPass 6.8.x prior to 6.8.5-HF, ClearPass 6.9.x prior to 6.9.1
Affected Version To: ClearPass 6.7.0
Patch Exists: YES
Related CWE: CVE-2020-7115
CPE: a:arubanetworks:clearpass_policy_manager:6.7.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: RHEL/CentOS 7.x
2020
Aruba ClearPass Policy Manager 6.7.0 – Unauthenticated Remote Command Execution
Aruba ClearPass Policy Manager 6.7.0 is vulnerable to unauthenticated remote command execution. An attacker can exploit this vulnerability by sending a malicious OpenSSL engine to the vulnerable server. This will allow the attacker to execute arbitrary commands on the server.
Mitigation:
Upgrade to ClearPass 6.7.13-HF, ClearPass 6.8.5-HF, or ClearPass 6.9.1