CVE-2023-43508
EUVD-2023-4791425.10.2023, 18:17
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| arubanetworks | clearpass_policy_manager | 𝑥 < 6.9.13 |
| arubanetworks | clearpass_policy_manager | 6.10.0 ≤ 𝑥 < 6.10.8 |
| arubanetworks | clearpass_policy_manager | 6.11.0 ≤ 𝑥 ≤ 6.11.4 |
| arubanetworks | clearpass_policy_manager | 6.9.13 |
| arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_2 |
| arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_3 |
| arubanetworks | clearpass_policy_manager | 6.10.8 |
| arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_2 |
| arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_5 |
𝑥
= Vulnerable software versions