Aruba ClearPass versions 6.6.x before 6.6.9 and 6.7.x before 6.7.1 are vulnerable to CSRF attacks, allowing unauthorized manipulation of authenticated users. Learn how to mitigate this security risk.
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users.
Understanding CVE-2018-7060
The web administrative interface of Aruba ClearPass is susceptible to cross-site request forgery (CSRF) attacks targeting authenticated users.
What is CVE-2018-7060?
The Impact of CVE-2018-7060
Technical Details of CVE-2018-7060
Aruba ClearPass is affected by the following:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take: