Authenticated Information Disclosure in ClearPass Policy Manager Web-Based Management Interface
CVE-2023-25591

6.5MEDIUM

Key Information:

Vendor
HP (HP)
Status
Aruba Clearpass Policy Manager
Vendor
CVE Published:
22 March 2023

Summary

A vulnerability exists within the web-based management interface of ClearPass Policy Manager that can enable a remote attacker with minimal privileges to gain unauthorized access to sensitive information. Exploiting this flaw could allow the attacker to gather information that may lead to an escalation of privileges within the ClearPass environment, thereby compromising the security of the system.

Affected Version(s)

Aruba ClearPass Policy Manager 6.11.1 and below

Aruba ClearPass Policy Manager 6.10.8 and below

Aruba ClearPass Policy Manager 6.9.13 and below

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luke Young (bugcrowd.com/bored_engineer)
.