← Vulnerability feed

Vulnerability record · CVE-2018-7058 · published 6 August 2018

CVE-2018-7058: Hp aruba clearpass policy manager improper authentication vulnerability

Hp · Aruba Clearpass Policy Manager

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

9.8 CVSS 3.0 Critical EPSS 3.9% · top 10.1% CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 10.0
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7058 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-5824Hp aruba clearpass policy manager vulnerabilityAn unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 19%8.8CVE-2018-7059Hp aruba clearpass policy manager improper input validation vulnerabilityAruba ClearPass prior to 6.6.9 has a vulnerability in the API that helps to coordinate cluster actions. An authenticated user with the "mon" permissi…EPSS 1.1%8.8CVE-2017-5825Hp aruba clearpass policy manager vulnerabilityA privilege escalation vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 1.8%8.8CVE-2017-5826Hp aruba clearpass policy manager vulnerabilityAn authenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 3.3%8.1CVE-2017-9001Hp aruba clearpass policy manager vulnerabilityAruba ClearPass 6.6.3 and later includes a feature called "SSH Lockout", which causes ClearPass to lock accounts with too many login failures through…EPSS 7.3%8.1CVE-2017-5828Hp aruba clearpass policy manager xml external entity (xxe) vulnerabilityAn arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 1.9%7.8CVE-2017-5829Hp aruba clearpass policy manager vulnerabilityAn access restriction bypass vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.EPSS 0.59%7.5CVE-2018-5390Linux kernel TCP out-of-order queue processing denial of serviceLinux kernel versions 4.9 and later can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incomi…EPSS 74%analysed

Source: NIST National Vulnerability Database (record CVE-2018-7058), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.