Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5wv-8cpq-h4x2

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.

In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.

EPSS

Процентиль: 65%
0.00487
Низкий

8.1 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.1
nvd
около 7 лет назад

In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been disabled may still be able to perform read/write operations on parts of the XML API. This can lead to unauthorized access to the API and complete compromise of the ClearPass instance if an attacker knows of the existence of these accounts.

EPSS

Процентиль: 65%
0.00487
Низкий

8.1 High

CVSS3

Дефекты

CWE-611