Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

ClearPass and CVE-2016-2118

This thread has been viewed 0 times
  • 1.  ClearPass and CVE-2016-2118

    Posted Apr 13, 2016 01:22 PM

    ClearPass uses Samba internally which is affected by security advisory CVE-2016-2118 (aka "Badlock").

     

    According to RedHat:

     

    "An Active Directory infrastructure with a Samba server as a domain member is vulnerable to this flaw, as a man-in-the-middle attacker could intercept traffic between the domain member and the domain controller to impersonate the client and get the same privileges as the authenticated user account."

     

    We need guidance from Aruba on what steps they are taking to resolve this within the ClearPass product and how long the wait will be.

     

    Thanks.

     

     



  • 2.  RE: ClearPass and CVE-2016-2118

    EMPLOYEE
    Posted Apr 13, 2016 01:29 PM

    Hi Bruce,

    I have to have engineering check on this one.

     

    In future, can you send security vulnerability questions to sirt@arubanetworks.com so that the right folks see these types of questions immediately? Details on this email address and security policies in general are posted here http://www.arubanetworks.com/support-services/security-bulletins/

     

    Best regards,

     

    Madani



  • 3.  RE: ClearPass and CVE-2016-2118

    EMPLOYEE
    Posted Apr 16, 2016 05:15 PM

    Bruce,

    I wanted to drop you a note to let you know we have not forgotten you. Our security team is involved and continues to investigate.

     

    Best regards,

     

    Madani



  • 4.  RE: ClearPass and CVE-2016-2118

    EMPLOYEE
    Posted Apr 22, 2016 10:02 PM

    Bruce,

    We've posted the SAMR and LSA man in the middle attacks ("BADLOCK") advisory. Please let me know if you have any questions.

     

    Best regards,

     

    Madani

     

     



  • 5.  RE: ClearPass and CVE-2016-2118

    Posted Apr 25, 2016 11:05 AM

    Thank you for keeping on top of this. Good to see such a quick turnaround.