Arubanetworks Clearpass Policy Manager vulnerabilities
140 known vulnerabilities affecting arubanetworks/clearpass_policy_manager.
Total CVEs
140
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH73MEDIUM45LOW1
Vulnerabilities
Page 3 of 7
CVE-2022-43536HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72023-01-05
CVE-2022-43536 [HIGH] CWE-78 CVE-2022-43536: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ver
nvd
CVE-2022-43532MEDIUMCVSS 4.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72023-01-05
CVE-2022-43532 [MEDIUM] CWE-79 CVE-2022-43532: A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an au
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affec
nvd
CVE-2022-43539MEDIUMCVSS 4.5≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72023-01-05
CVE-2022-43539 [MEDIUM] CWE-200 CVE-2022-43539: A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an att
A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster i
nvd
CVE-2022-43540MEDIUMCVSS 5.5≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72023-01-05
CVE-2022-43540 [MEDIUM] CWE-200 CVE-2022-43540: A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local m
A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7
nvd
CVE-2022-23693HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23693 [HIGH] CWE-89 CVE-2022-23693: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
nvd
CVE-2022-23694HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23694 [HIGH] CWE-89 CVE-2022-23694: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
nvd
CVE-2022-37878HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37878 [HIGH] CWE-78 CVE-2022-37878: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-23692HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23692 [HIGH] CWE-89 CVE-2022-23692: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
nvd
CVE-2022-37882HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37882 [HIGH] CWE-78 CVE-2022-37882: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-37884HIGHCVSS 7.5≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37884 [HIGH] CWE-400 CVE-2022-37884: A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauth
A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker to send specific operations which result in a Denial-of-Service condition. A successful exploitation of this vulnerability results in the unavailability of the guest interface in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10
nvd
CVE-2022-37879HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37879 [HIGH] CWE-77 CVE-2022-37879: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-37880HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37880 [HIGH] CWE-78 CVE-2022-37880: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-23685HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23685 [HIGH] CWE-352 CVE-2022-23685: A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes
A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against these endpoints if the attacker can convince an authenticated user of the interface to interac
nvd
CVE-2022-37883HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37883 [HIGH] CWE-77 CVE-2022-37883: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-23695HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23695 [HIGH] CWE-89 CVE-2022-23695: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
nvd
CVE-2022-23696HIGHCVSS 8.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-23696 [HIGH] CWE-89 CVE-2022-23696: Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an aut
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to comple
nvd
CVE-2022-37881HIGHCVSS 7.2≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37881 [HIGH] CWE-77 CVE-2022-37881: Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenti
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager ve
nvd
CVE-2022-37877HIGHCVSS 7.8≥ 6.9.0, < 6.9.12≥ 6.10.0, < 6.10.72022-09-20
CVE-2022-37877 [HIGH] CVE-2022-37877: A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has
nvd
CVE-2022-23669HIGHCVSS 8.8≤ 6.7.14≥ 6.8.0, < 6.8.9+3 more2022-05-17
CVE-2022-23669 [HIGH] CWE-613 CVE-2022-23669: A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version
A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
nvd
CVE-2022-23671HIGHCVSS 7.5≤ 6.7.14≥ 6.8.0, < 6.8.9+3 more2022-05-17
CVE-2022-23671 [HIGH] CVE-2022-23671: A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy
A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
nvd