7.2
CVE-2018-7079
- EPSS 0.34%
- Veröffentlicht 07.12.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:36
- Quelle security-alert@hpe.com
- Teams Watchlist Login
- Unerledigt Login
Aruba ClearPass Policy Manager guest authorization failure. Certain administrative operations in ClearPass Guest do not properly enforce authorization rules, which allows any authenticated administrative user to execute those operations regardless of privilege level. This could allow low-privilege users to view, modify, or delete guest users. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Clearpass Policy Manager Version < 6.6.10
Arubanetworks ≫ Clearpass Policy Manager Version >= 6.7.0 < 6.7.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.535 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.