4.9
CVSSv2

CVE-2014-2071

Published: 08/01/2018 Updated: 31/01/2018
CVSS v2 Base Score: 4.9 | Impact Score: 6.4 | Exploitability Score: 4.4
CVSS v3 Base Score: 7.1 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 436
Vector: AV:A/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x prior to 6.2.5.61640 and 6.3.x prior to 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.

Vulnerable Product Search on Vulmon Subscribe to Product

arubanetworks clearpass