CVE-2024-51772Command Injection in Clearpass Policy Manager

CWE-77Command Injection3 documents3 sources
Severity
8.0HIGHNVD
CNA6.4
EPSS
0.4%
top 39.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3

Description

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Authenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)2024-12-03
GHSA
GHSA-88r2-xrwf-mvhm: An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary c2024-12-03
CVE-2024-51772 — Command Injection | cvebase