CVE-2018-7067
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 30% of all CVEs
observed exploitation
nono source reports it
A Remote Authentication bypass in Aruba ClearPass Policy Manager leads to complete cluster compromise. An authentication flaw in all versions of ClearPass could allow an attacker to compromise the entire cluster through a specially crafted API call. Network access to the administrative web interface is required to exploit this vulnerability. Resolution: Fixed in 6.7.6 and 6.6.10-hotfix.
Affected products
Hewlett Packard Enterprise · Aruba ClearPass Policy Manager