CVE-2025-23058
04.02.2025, 18:15
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | clearpass_policy_manager | 6.11.0 ≤ 𝑥 < 6.11.10 |
arubanetworks | clearpass_policy_manager | 6.12.0 ≤ 𝑥 < 6.12.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration