CVE-2025-23058 — Weak Authentication in Clearpass Policy Manager
Severity
8.1HIGHNVD
CNA8.8
EPSS
0.1%
top 66.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 4
Description
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2
Affected Packages2 packages
▶CVEListV5hewlett_packard_enterprise/hpe_aruba_networking_clearpass_policy_manager6.12.0 — <=6.12.3+1
🔴Vulnerability Details
2CVEList▶
Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management Interface↗2025-02-04
GHSA▶
GHSA-vhj8-f69q-35j6: A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to ga↗2025-02-04