CVE-2025-23058Weak Authentication in Clearpass Policy Manager

Severity
8.1HIGHNVD
CNA8.8
EPSS
0.1%
top 66.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4

Description

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management Interface2025-02-04
GHSA
GHSA-vhj8-f69q-35j6: A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to ga2025-02-04
CVE-2025-23058 — Weak Authentication | cvebase