CVE-2023-25594
Authorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based Management Interface
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Produtos afetados
Hewlett Packard Enterprise (HPE) · Aruba ClearPass Policy ManagerQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →