CVE-2018-7079

HIGH

Aruba ClearPass Policy Manager < 6.6.10 - Authenticated Incorrect Authorization

Title source: llm
STIX 2.1

Description

Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0034
EPSS Percentile 56.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
arubanetworks/clearpass_policy_manager < 6.6.10
Published Dec 07, 2018
Tracked Since Feb 18, 2026