SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7113

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts.

MEDIUM 4.9EPSS 0.85%

Does this matter?

Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability was found when an attacker, while communicating with the ClearPass management interface, is able to intercept and change parameters in the HTTP packets resulting in the compromise of some of ClearPass' service accounts. Resolution: Fixed in 6.7.10, 6.8.1, 6.9.0 and higher.

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
0.85% probability · 56th percentile
CISA KEV
Not listed
Affected
arubanetworks/clearpass
Source
security-alert@hpe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.