CVE-2016-4401: Arubanetworks Clearpass

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

Affected products

  • Arubanetworks Clearpass: before 6.5.7 (fixed in 6.5.7); from 6.6.0, before 6.6.2 (fixed in 6.6.2)

Published 2019-11-06. Last modified 2026-06-17.