CVE-2023-25595

 A vulnerability exists in the ClearPass OnGuard Ubuntu agentthat allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard environment.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
hpeCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
arubanetworksclearpass_policy_manager
6.9.0 ≤
𝑥
≤ 6.9.13
arubanetworksclearpass_policy_manager
6.10.0 ≤
𝑥
≤ 6.10.8
arubanetworksclearpass_policy_manager
6.11.0
arubanetworksclearpass_policy_manager
6.11.1
𝑥
= Vulnerable software versions