CVE-2024-51773
published 2024-12-03CVE-2024-51773: A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.27%
18.3th percentile
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arubanetworks | clearpass_policy_manager | >= 6.11.0 < 6.11.10 | 6.11.10 |
| arubanetworks | clearpass_policy_manager | >= 6.12.0 < 6.12.3 | 6.12.3 |
| hewlett_packard_enterprise | hpe_aruba_networking_clearpass_policy_manager | 6.11.0 – 6.11.9 | — |
| hewlett_packard_enterprise | hpe_aruba_networking_clearpass_policy_manager | 6.12.0 – 6.12.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-03
Published