Vulnerabilities > Arubanetworks > Clearpass Policy Manager > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-02-23 CVE-2021-26681 Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-77
critical
9.0
2021-02-23 CVE-2021-26683 Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-77
critical
9.0
2021-02-23 CVE-2021-26684 Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-77
critical
9.0
2020-06-03 CVE-2020-7115 Missing Authentication for Critical Function vulnerability in Arubanetworks Clearpass Policy Manager
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass.
network
low complexity
arubanetworks CWE-306
critical
9.8
2020-06-03 CVE-2020-7116 Improper Input Validation vulnerability in Arubanetworks Clearpass Policy Manager
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution.
network
low complexity
arubanetworks CWE-20
critical
9.0
2020-06-03 CVE-2020-7117 Unspecified vulnerability in Arubanetworks Clearpass Policy Manager
The ClearPass Policy Manager WebUI administrative interface has an authenticated command remote execution.
network
low complexity
arubanetworks
critical
9.0
2018-12-07 CVE-2018-7066 Unspecified vulnerability in Arubanetworks Clearpass Policy Manager
An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices.
network
arubanetworks
critical
9.3
2017-10-16 CVE-2015-4650 Permissions, Privileges, and Access Controls vulnerability in Arubanetworks Clearpass Policy Manager
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.
network
low complexity
arubanetworks CWE-264
critical
10.0
2015-05-28 CVE-2014-6628 Remote Code Execution vulnerability in Aruba Networks ClearPass Policy Manager
Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via unspecified vectors.
network
low complexity
arubanetworks
critical
9.0
2015-05-28 CVE-2015-1550 Path Traversal vulnerability in Arubanetworks Clearpass Policy Manager
Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors.
network
low complexity
arubanetworks CWE-22
critical
9.0