CVE-2018-7066
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits administrators to link other network devices into ClearPass for the purpose of collecting enhanced information about connected endpoints. A defect in the API could allow a remote attacker to execute arbitrary commands on one of the linked devices. This vulnerability is only applicable if credentials for devices have been supplied to ClearPass under Configuration -> Network -> Devices -> CLI Settings. Resolution: Fixed in 6.7.5 and 6.6.10-hotfix.
Existe una ejecución remota de comandos sin autenticar en Aruba ClearPass Policy Manager en dispositivos enlazados. La característica ClearPass OnConnect permite que los administradores conecten otros dispositivos de red en ClearPass para recopilar información mejorada sobre los endpoints conectados. Un defecto en la API podría permitir que un atacante remoto ejecute comandos arbitrarios en uno de los dispositivos enlazados. La vulnerabilidad solo es aplicable si las credenciales para los dispositivos se han proporcionado a ClearPass en Configuration ->Network ->Devices ->CLI Settings. Solución: solucionado en 6.7.5 y 6.6.10-hotfix.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-15 CVE Reserved
- 2018-12-07 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-007.txt | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | < 6.6.10 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " < 6.6.10" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | >= 6.7.0 < 6.7.5 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " >= 6.7.0 < 6.7.5" | - |
Affected
|