CVE-2018-7065
https://notcve.org/view.php?id=CVE-2018-7065
An authenticated SQL injection vulnerability in Aruba ClearPass Policy Manager can lead to privilege escalation. All versions of ClearPass are affected by multiple authenticated SQL injection vulnerabilities. In each case, an authenticated administrative user of any type could exploit this vulnerability to gain access to "appadmin" credentials, leading to complete cluster compromise. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix. Una vulnerabilidad de inyección SQL autenticada en Aruba ClearPass Policy Manager puede conducir al escalado de privilegios. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-007.txt • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2018-7080
https://notcve.org/view.php?id=CVE-2018-7080
A vulnerability exists in the firmware of embedded BLE radios that are part of some Aruba Access points. An attacker who is able to exploit the vulnerability could install new, potentially malicious firmware into the AP's BLE radio and could then gain access to the AP's console port. This vulnerability is applicable only if the BLE radio has been enabled in affected access points. The BLE radio is disabled by default. Note - Aruba products are NOT affected by a similar vulnerability being tracked as CVE-2018-16986. • http://www.securityfocus.com/bid/105814 https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-006.txt •
CVE-2018-7067
https://notcve.org/view.php?id=CVE-2018-7067
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through a specially crafted API call. Network access to the administrative web interface is required to exploit this vulnerability. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix. Una omisión de autenticación remota en Aruba ClearPass Policy Manager conduce al compromiso total del clúster. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-007.txt • CWE-287: Improper Authentication •
CVE-2018-7060
https://notcve.org/view.php?id=CVE-2018-7060
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface. Aruba ClearPass en versiones 6.6.x anteriores a la 6.6.9 y versiones 6.7.x anteriores a la 6.7.1 es vulnerable a ataques de Cross-Site Request Forgery (CSRF) contra usuarios autenticados. Un atacante podría manipular a un usuario autenticado para qu realice acciones en la interfaz web administrativa. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-2592
https://notcve.org/view.php?id=CVE-2014-2592
Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension. Vulnerabilidad de subida de archivos sin restricción en el portal Aruba Web Management permite que atacantes remotos ejecuten código arbitrario subiendo un archivo con una extensión ejecutable. • https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2592 • CWE-434: Unrestricted Upload of File with Dangerous Type •