Unauthenticated Endpoint Allows Sending Arbitrary OnGuard Notifications
CVE-2023-43509

5.8MEDIUM

Key Information:

Vendor

HP

Vendor
CVE Published:
25 October 2023

What is CVE-2023-43509?

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.

Affected Version(s)

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.11.x: 6.11.4 and below

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.10.x: 6.10.8 with ClearPass 6.10.8 Cumulative Hotfix Patch 5 and below

Aruba ClearPass Policy Manager ClearPass Policy Manager 6.9.x: 6.9.13 with ClearPass 6.9.13 Cumulative Hotfix Patch 3 and below

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Luke Young (bugcrowd.com/bored-engineer)
.
CVE-2023-43509 : Unauthenticated Endpoint Allows Sending Arbitrary OnGuard Notifications