CVE-2023-43508
25.10.2023, 18:17
Vulnerabilities in the web-based management interface ofClearPass Policy Manager allow an attacker with read-onlyprivileges to perform actions that change the state of theClearPass Policy Manager instance. Successful exploitationof these vulnerabilities allow an attacker to completestate-changing actions in the web-based management interfacethat should not be allowed by their current level ofauthorization on the platform.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | clearpass_policy_manager | 𝑥 < 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.10.0 ≤ 𝑥 < 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.11.0 ≤ 𝑥 ≤ 6.11.4 |
arubanetworks | clearpass_policy_manager | 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_3 |
arubanetworks | clearpass_policy_manager | 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_5 |
𝑥
= Vulnerable software versions