cbcvebase.

Hewlett Packard Enterprise Clearpass Policy Manager vulnerabilities

36 known vulnerabilities affecting hewlett_packard_enterprise/clearpass_policy_manager.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2026-73786P3HIGHCVSS 7.5≥ 6.11.0, ≤ 6.11.142026-09-09
CVE-2026-73786 [HIGH] CWE-400 CVE-2026-73786: A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.
nvd
CVE-2026-79811P3HIGHCVSS 7.2≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79811 [HIGH] CVE-2026-79811: A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authentica A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.
nvd
CVE-2026-79806P3HIGHCVSS 7.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79806 [HIGH] CVE-2026-79806: A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.
nvd
CVE-2026-79807P3HIGHCVSS 7.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79807 [HIGH] CVE-2026-79807: A missing integrity verification vulnerability in the Windows client software for ClearPass Policy M A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.
nvd
CVE-2026-79808P3HIGHCVSS 7.8≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79808 [HIGH] CVE-2026-79808: A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.
nvd
CVE-2026-73788P3MEDIUMCVSS 6.5≥ 6.12.0, ≤ 6.12.8≥ 6.11.0, ≤ 6.11.142026-09-09
CVE-2026-73788 [MEDIUM] CWE-269 CVE-2026-73788: A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to eleva A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.
nvd
CVE-2026-79815P3MEDIUMCVSS 6.5≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79815 [MEDIUM] CVE-2026-79815: A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an au A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint.
nvd
CVE-2026-73789P4MEDIUMCVSS 5.3≥ 6.12.0, ≤ 6.12.8≥ 6.11.0, ≤ 6.11.142026-09-09
CVE-2026-73789 [MEDIUM] CWE-284 CVE-2026-73789: A vulnerability in the web-based management interface of CPPM guest account management services coul A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.
nvd
CVE-2026-79814P4MEDIUMCVSS 6.7≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79814 [MEDIUM] CVE-2026-79814: An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow mali An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met. Successful exploitation could allow a local attacker to execute arbitrary code with elevated privileges on the affected system
nvd
CVE-2026-79816P4MEDIUMCVSS 6.3≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79816 [MEDIUM] CVE-2026-79816: A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unau A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a victim's browser context within the aff
nvd
CVE-2026-79813P4MEDIUMCVSS 6.7≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79813 [MEDIUM] CVE-2026-79813: A local privilege escalation vulnerability exists in the ClearPass client software. Successful explo A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met.
nvd
CVE-2026-79818P4MEDIUMCVSS 5.3≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79818 [MEDIUM] CVE-2026-79818: A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remot A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.
nvd
CVE-2024-41916P4MEDIUMCVSS 4.9≥ ClearPass Policy Manager 6.12.1 and below, ≤ <=6.12.1≥ ClearPass Policy Manager 6.11.8 and below, ≤ <=6.11.82024-07-30
CVE-2024-41916 [MEDIUM] CVE-2024-41916: A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative p A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
nvd
CVE-2024-5486P4MEDIUMCVSS 4.9≥ ClearPass Policy Manager 6.12.1 and below, ≤ <=6.12.1≥ ClearPass Policy Manager 6.11.8 and below, ≤ <=6.11.82024-07-30
CVE-2024-5486 [MEDIUM] CVE-2024-5486: A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative p A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager
nvd
CVE-2026-79817P4MEDIUMCVSS 5.5≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79817 [MEDIUM] CVE-2026-79817: A sensitive information disclosure vulnerability exists in the client software of HPE Networking Cle A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.
nvd
CVE-2026-79812P4MEDIUMCVSS 6.1≥ 6.14.0, ≤ 6.14.0≥ 6.11.0, ≤ 6.11.152026-10-06
CVE-2026-79812 [MEDIUM] CVE-2026-79812: A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Man A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service.
nvd
Hewlett Packard Enterprise Clearpass Policy Manager vulnerabilities | cvebase