CVE-2018-7059

HIGH

Aruba ClearPass < 6.6.9 - Authenticated Privilege Escalation via Cluster API

Title source: llm
STIX 2.1

Description

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 58.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
hp/aruba_clearpass_policy_manager < 6.6.9
Published Aug 06, 2018
Tracked Since Feb 18, 2026