CVE-2022-43540Sensitive Information Exposure in Clearpass Policy Manager

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 82.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5

Description

A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5hewlett_packard_enterprise/aruba_clearpass_policy_managerClearPass Policy Manager 6.10.x: 6.10.7 and below, ClearPass Policy Manager 6.9.x: 6.9.12 and below

🔴Vulnerability Details

2
GHSA
GHSA-35p7-xx3v-q6v2: A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensiti2023-01-05
CVEList
CVE-2022-43540: A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensiti2023-01-03
CVE-2022-43540 — Sensitive Information Exposure | cvebase