Unauthenticated Endpoint Allows Sending Arbitrary OnGuard Notifications
CVE-2023-43509

5.8MEDIUM

Key Information:

Vendor
HP
Vendor
CVE Published:
25 October 2023

Summary

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.

Affected Version(s)

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.11.x: 6.11.4 and below

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.10.x: 6.10.8 with ClearPass 6.10.8 Cumulative Hotfix Patch 5 and below

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.9.x: 6.9.13 with ClearPass 6.9.13 Cumulative Hotfix Patch 3 and below

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luke Young (bugcrowd.com/bored-engineer)
.