CVE-2020-7114 Information

Description

A vulnerability exists allowing attackers when present in the same network segment as ClearPass’ management interface to make changes to certain databases in ClearPass by crafting HTTP packets. As a result of this attack a possible complete cluster compromise might occur. Resolution: Fixed in 6.7.13 6.8.4 6.9.0 and higher.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-004.txt

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: