Vulnerability record · CVE-2020-7115 · published 3 June 2020
CVE-2020-7115: Aruba ClearPass Policy Manager web interface authentication bypass to RCE
Arubanetworks · Clearpass Policy Manager
The ClearPass Policy Manager web interface contains a missing-authentication flaw (CWE-306) that allows an attacker to bypass authentication. After bypassing, the attacker can run an exploit that achieves remote command execution on the underlying operating system. This matters because the interface is network-exposed and the flaw chains directly to full host compromise.
Description
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass chaining to remote command execution with a CVSS of 9.8 and high EPSS.
What it is
The ClearPass Policy Manager web interface contains a missing-authentication flaw (CWE-306) that allows an attacker to bypass authentication. After bypassing, the attacker can run an exploit that achieves remote command execution on the underlying operating system. This matters because the interface is network-exposed and the flaw chains directly to full host compromise.
Impact
An unauthenticated attacker gains the ability to execute arbitrary commands on the underlying operating system, leading to full compromise of the ClearPass host and any data or credentials it handles.
Attack surface
Reachable over the network via the ClearPass Policy Manager web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.646 probability, 99.2nd percentile) and public references are tagged Exploit, indicating working exploit code is publicly available.
What to do
- Upgrade to a fixed release: 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 or higher.
- Restrict network access to the ClearPass web interface to trusted management networks only.
- Place the management interface behind a firewall or VPN; do not expose it to the internet.
- Rotate credentials and secrets stored or processed by the ClearPass host after patching, assuming possible prior compromise.
- Monitor vendor advisory ARUBA-PSA-2020-005 for any updated guidance.
Detection
- Review web server and application logs for unauthenticated requests to administrative endpoints or anomalous request patterns preceding command execution.
- Hunt for unexpected child processes spawned by the ClearPass web service (for example shells or system utilities).
- Alert on outbound network connections from the ClearPass host to unfamiliar destinations.
- Audit authentication logs for access to privileged functions without a preceding successful login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158368/ClearPass-Policy-Manager-Unauthenticated-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-005.txt | Vendor Advisory |
| http://packetstormsecurity.com/files/158368/ClearPass-Policy-Manager-Unauthenticated-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2020-005.txt | Vendor Advisory |
Track CVE-2020-7115 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7115), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.