CVE-2018-7079
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
Error de autorización de invitados en Aruba ClearPass Policy Manager. Ciertas operaciones administrativas en el invitado de ClearPass no aplican correctamente las reglas de autorización, lo que permite que cualquier usuario administrativo autenticado ejecute dichas operaciones, independientemente del nivel de privilegios. Esto podría permitir que usuarios con pocos privilegios vean modifiquen o eliminen usuarios invitados. Solución: solucionado en 6.7.6 y 6.6.10-hotfix.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-15 CVE Reserved
- 2018-12-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-007.txt | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | < 6.6.10 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " < 6.6.10" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | >= 6.7.0 < 6.7.6 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " >= 6.7.0 < 6.7.6" | - |
Affected
|