Vulnerabilities > Arubanetworks > Clearpass > 6.7.3

DATE CVE VULNERABILITY TITLE RISK
2020-04-16 CVE-2020-7113 Information Exposure vulnerability in Arubanetworks Clearpass
A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts.
network
low complexity
arubanetworks CWE-200
4.0
2020-04-16 CVE-2020-7111 Injection vulnerability in Arubanetworks Clearpass
A server side injection vulnerability exists which could allow an authenticated administrative user to achieve Remote Code Execution in ClearPass.
network
low complexity
arubanetworks CWE-74
6.5
2020-04-16 CVE-2020-7110 Cross-site Scripting vulnerability in Arubanetworks Clearpass
ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack.
3.5