CVE-2018-7060: Arubanetworks Clearpass
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.
Affected products
- Arubanetworks Clearpass: from 6.6.0, before 6.6.9 (fixed in 6.6.9); from 6.7.0, before 6.7.1 (fixed in 6.7.1)
Published 2018-08-06. Last modified 2026-06-17.