CVE-2024-26302

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
hpeCNA
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
arubanetworksclearpass_policy_manager
6.9.0 ≤
𝑥
< 6.9.13
arubanetworksclearpass_policy_manager
6.10.0 ≤
𝑥
< 6.10.8
arubanetworksclearpass_policy_manager
6.11.0 ≤
𝑥
≤ 6.11.6
arubanetworksclearpass_policy_manager
6.9.13
arubanetworksclearpass_policy_manager
6.9.13:cumulative_hotfix_patch_2
arubanetworksclearpass_policy_manager
6.9.13:cumulative_hotfix_patch_3
arubanetworksclearpass_policy_manager
6.9.13:cumulative_hotfix_patch_4
arubanetworksclearpass_policy_manager
6.10.8
arubanetworksclearpass_policy_manager
6.10.8:cumulative_hotfix_patch_2
arubanetworksclearpass_policy_manager
6.10.8:cumulative_hotfix_patch_5
arubanetworksclearpass_policy_manager
6.10.8:cumulative_hotfix_patch_6
arubanetworksclearpass_policy_manager
6.12.0
𝑥
= Vulnerable software versions