CVE-2023-43509
25.10.2023, 18:17
A vulnerability in the web-based management interface ofClearPass Policy Manager could allow an unauthenticatedremote attacker to send notifications to computers that arerunning ClearPass OnGuard. These notifications can then beused to phish users or trick them into downloading malicioussoftware.
Vendor | Product | Version |
---|---|---|
arubanetworks | clearpass_policy_manager | 𝑥 < 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.10.0 ≤ 𝑥 < 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.11.0 ≤ 𝑥 ≤ 6.11.4 |
arubanetworks | clearpass_policy_manager | 6.9.13 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.9.13:cumulative_hotfix_patch_3 |
arubanetworks | clearpass_policy_manager | 6.10.8 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_2 |
arubanetworks | clearpass_policy_manager | 6.10.8:cumulative_hotfix_patch_5 |
𝑥
= Vulnerable software versions