← Vulnerability feed

Vulnerability record · CVE-2020-7115 · published 3 June 2020

CVE-2020-7115: Aruba ClearPass Policy Manager web interface authentication bypass to RCE

Arubanetworks · Clearpass Policy Manager

The ClearPass Policy Manager web interface contains a missing-authentication flaw (CWE-306) that allows an attacker to bypass authentication. After bypassing, the attacker can run an exploit that achieves remote command execution on the underlying operating system. This matters because the interface is network-exposed and the flaw chains directly to full host compromise.

9.8 CVSS 3.1 Critical EPSS 65% · top 0.8% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 10.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 and higher.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass chaining to remote command execution with a CVSS of 9.8 and high EPSS.

What it is

The ClearPass Policy Manager web interface contains a missing-authentication flaw (CWE-306) that allows an attacker to bypass authentication. After bypassing, the attacker can run an exploit that achieves remote command execution on the underlying operating system. This matters because the interface is network-exposed and the flaw chains directly to full host compromise.

Impact

An unauthenticated attacker gains the ability to execute arbitrary commands on the underlying operating system, leading to full compromise of the ClearPass host and any data or credentials it handles.

Attack surface

Reachable over the network via the ClearPass Policy Manager web interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.646 probability, 99.2nd percentile) and public references are tagged Exploit, indicating working exploit code is publicly available.

What to do

  • Upgrade to a fixed release: 6.7.13-HF, 6.8.5-HF, 6.8.6, 6.9.1 or higher.
  • Restrict network access to the ClearPass web interface to trusted management networks only.
  • Place the management interface behind a firewall or VPN; do not expose it to the internet.
  • Rotate credentials and secrets stored or processed by the ClearPass host after patching, assuming possible prior compromise.
  • Monitor vendor advisory ARUBA-PSA-2020-005 for any updated guidance.

Detection

  • Review web server and application logs for unauthenticated requests to administrative endpoints or anomalous request patterns preceding command execution.
  • Hunt for unexpected child processes spawned by the ClearPass web service (for example shells or system utilities).
  • Alert on outbound network connections from the ClearPass host to unfamiliar destinations.
  • Audit authentication logs for access to privileged functions without a preceding successful login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7115 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed10.0CVE-2022-23657Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF…EPSS 3.2%10.0CVE-2022-23658Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF…EPSS 2.8%10.0CVE-2022-23660Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF…EPSS 2.8%9.8CVE-2023-25589Arubanetworks clearpass policy manager missing authentication for critical function vulnerabilityA vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary …EPSS 0.96%9.8CVE-2021-40996Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.…EPSS 1.8%9.8CVE-2021-40997Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.…EPSS 1.8%9.8CVE-2021-37736Arubanetworks clearpass policy manager vulnerabilityA remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-7115), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.