CVE-2023-43506

EUVD-2023-47912
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
hpeCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
arubanetworksclearpass_policy_manager
𝑥
< 6.9.13
arubanetworksclearpass_policy_manager
6.10.0 ≤
𝑥
< 6.10.8
arubanetworksclearpass_policy_manager
6.11.0 ≤
𝑥
≤ 6.11.4
arubanetworksclearpass_policy_manager
6.9.13
arubanetworksclearpass_policy_manager
6.9.13:cumulative_hotfix_patch_2
arubanetworksclearpass_policy_manager
6.9.13:cumulative_hotfix_patch_3
arubanetworksclearpass_policy_manager
6.10.8
arubanetworksclearpass_policy_manager
6.10.8:cumulative_hotfix_patch_2
arubanetworksclearpass_policy_manager
6.10.8:cumulative_hotfix_patch_5
𝑥
= Vulnerable software versions