CVE-2023-25594
22.03.2023, 06:15
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-onlyprivileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitationof this vulnerability allows an attacker to completestate-changing actions in the web-based management interfacethat should not be allowed by their current level of authorization on the platform.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | clearpass_policy_manager | 6.9.0 ≤ 𝑥 ≤ 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.10.0 ≤ 𝑥 ≤ 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.11.0 |
arubanetworks | clearpass_policy_manager | 6.11.1 |
𝑥
= Vulnerable software versions