CVE-2018-7079
HIGHAruba ClearPass Policy Manager < 6.6.10 - Authenticated Incorrect Authorization
Title source: llmDescription
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-007.txt
Scores
CVSS v3
7.2
EPSS
0.0034
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-863
Status
published
Products (1)
arubanetworks/clearpass_policy_manager
< 6.6.10
Published
Dec 07, 2018
Tracked Since
Feb 18, 2026