Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows remote attackers to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Aruba Networks 多款产品访问安全绕过漏洞
Vulnerability Description
Aruba Networks ClearPass和ClearPass Guest(旧称Amigopod)都是美国安移通网络(Aruba Networks)公司的产品。ClearPass是一套集成了网络控制功能、应用和设备管理功能的接入管理系统。ClearPass Guest是一套访客管理解决方案。 Aruba Networks ClearPass和ClearPass Guest中的Sponsorship Confirmation功能中存在安全绕过漏洞,该漏洞源于产品没有正确限制对赞助商批准页面的访问。远程
CVSS Information
N/A
Vulnerability Type
N/A