CVE-2023-25595Improper Access Control in Clearpass Policy Manager

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 22

Description

A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard environment.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5hewlett_packard_enterprise/aruba_clearpass_policy_manager6.10.8 and below, 6.11.1 and below, 6.9.13 and below+2

🔴Vulnerability Details

2
GHSA
GHSA-c2r9-vh8c-wg3c: A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensi2023-03-22
CVEList
Sensitive Information Disclosure in ClearPass OnGuard Ubuntu Agent2023-03-14
CVE-2023-25595 — Improper Access Control | cvebase