CVE-2018-7079
Last modified
CVE-2018-7079 is a vulnerability of currently unknown severity. Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Clearpass Policy Manager | < 6.6.10 |
| Arubanetworks | Clearpass Policy Manager | >= 6.7.0, < 6.7.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7079?
How severe is CVE-2018-7079?
How do I fix CVE-2018-7079?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7073A local arbitrary file modification vulnerability was identi…
- CVE-2018-7074A remote code execution vulnerability was identified in HPE …
- CVE-2018-7075A remote cross-site scripting (XSS) vulnerability was identi…
- CVE-2018-7076A remote code execution vulnerability was identified in HPE …
- CVE-2018-7077A security vulnerability in HPE XP P9000 Command View Advanc…
- CVE-2018-7078A remote code execution was identified in HPE Integrated Lig…
- CVE-2018-7080A vulnerability exists in the firmware of embedded BLE radio…
- CVE-2018-7081A remote code execution vulnerability is present in network-…9.8
- CVE-2018-7082A command injection vulnerability is present in Aruba Instan…7.2
- CVE-2018-7083If a process running within Aruba Instant crashes, it may le…
- CVE-2018-7084A command injection vulnerability is present that permits an…9.8
- CVE-2018-7085Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2018-7079?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
