CVE-2018-7058
Last modified
CVE-2018-7058 is a vulnerability of currently unknown severity. Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. EPSS estimates a 3.89% chance of exploitation in the next 30 days.
Description
Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Aruba Clearpass Policy Manager | >= 6.6.0, < 6.6.9 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7058?
How severe is CVE-2018-7058?
How do I fix CVE-2018-7058?
Are you affected by CVE-2018-7058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
