Authenticated Information Disclosure in ClearPass Policy Manager Web-Based Management Interface
CVE-2023-25591
6.5MEDIUM
What is CVE-2023-25591?
A vulnerability exists within the web-based management interface of ClearPass Policy Manager that can enable a remote attacker with minimal privileges to gain unauthorized access to sensitive information. Exploiting this flaw could allow the attacker to gather information that may lead to an escalation of privileges within the ClearPass environment, thereby compromising the security of the system.
Affected Version(s)
Aruba ClearPass Policy Manager 6.11.1 and below
Aruba ClearPass Policy Manager 6.10.8 and below
Aruba ClearPass Policy Manager 6.9.13 and below