CVE-2021-34614

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
arubanetworksclearpass_policy_manager
6.6.0 ≤
𝑥
≤ 6.6.10
arubanetworksclearpass_policy_manager
6.7.0 ≤
𝑥
≤ 6.7.14
arubanetworksclearpass_policy_manager
6.8.0 ≤
𝑥
< 6.8.9
arubanetworksclearpass_policy_manager
6.9.0 ≤
𝑥
< 6.9.6
𝑥
= Vulnerable software versions