Reflected Cross-Site Scripting Vulnerability in HPE Network Access Control Services
CVE-2025-37122
6.1MEDIUM
What is CVE-2025-37122?
A vulnerability exists in the web-based management interface of HPE's Network Access Control Services that allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS) attacks. If successfully exploited, attackers can execute arbitrary JavaScript code within the browser of a user interacting with the affected interface, potentially leading to unauthorized access and manipulation of user sessions. Organizations using these services should assess their exposure and implement necessary security measures to mitigate this risk.
Affected Version(s)
HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5
HPE Aruba Networking ClearPass Policy Manager 6.12.0 <= 6.12.5
HPE Aruba Networking ClearPass Policy Manager 6.11.0 <= 6.11.12