Back

HIGH

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions

Published Aug 6, 2018

Description

Aruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permission could use this vulnerability to obtain cluster credentials which could allow privilege escalation. This vulnerability is only present when authenticated as a user with "mon" permission.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hpe
Published Aug 6, 2018
Updated Aug 5, 2024
Reserved Feb 15, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a