CVE-2020-7115: Arubanetworks Clearpass Policy Manager
Critical severity, CVSS 9.8. EPSS: 64.6% chance of exploitation in the next 30 days.
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
Affected products
- Arubanetworks Clearpass Policy Manager: from 6.7.0, up to and including 6.7.13; from 6.8.0, before 6.8.6 (fixed in 6.8.6); from 6.9.0, before 6.9.1 (fixed in 6.9.1)
Published 2020-06-03. Last modified 2026-06-17.