CVE-2025-23060Cleartext Transmission of Sensitive Info in Clearpass Policy Manager

Severity
8.1HIGHNVD
CNA6.6
EPSS
0.1%
top 73.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateApr 6

Description

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling data tampering.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

7
OSV
linux-gcp, linux-gcp-4.15, linux-gcp-fips vulnerabilities2026-04-06
OSV
linux, linux-aws, linux-aws-hwe, linux-kvm, linux-oracle vulnerabilities2026-04-02
OSV
linux-fips vulnerabilities2026-04-02
OSV
linux-fips, linux-aws-fips vulnerabilities2026-04-02
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2026-04-01
CVE-2025-23060 — Clearpass Policy Manager vulnerability | cvebase