5
CVSSv2

CVE-2013-2269

Published: 01/10/2013 Updated: 08/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 up to and including 3.9.7, allows remote malicious users to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.

Vulnerable Product Search on Vulmon Subscribe to Product

arubanetworks clearpass 5.0.1

arubanetworks clearpass 5.1

arubanetworks clearpass 6.0.1

arubanetworks clearpass 5.2

arubanetworks clearpass 6.0.2

arubanetworks clearpass guest 3.0

arubanetworks clearpass guest 3.1

arubanetworks clearpass guest 3.2

arubanetworks clearpass guest 3.5

arubanetworks clearpass guest 3.9

arubanetworks clearpass guest 3.3

arubanetworks clearpass guest 3.7