« Volver al listado

CVE-2023-43509

Estado: ModificadaMedia (5.8)—

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-43509",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-43509",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-11T17:35:06.867846Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "Aruba ClearPass Policy Manager",
          "versions": [
            {
              "status": "affected",
              "version": "ClearPass Policy Manager 6.11.x: 6.11.4 and below",
              "versionType": "semver",
              "lessThanOrEqual": "<=6.11.4"
            },
            {
              "status": "affected",
              "version": "ClearPass Policy Manager 6.10.x: 6.10.8 with ClearPass 6.10.8 Cumulative Hotfix Patch 5 and below"
            },
            {
              "status": "affected",
              "version": "ClearPass Policy Manager 6.9.x: 6.9.13 with ClearPass 6.9.13 Cumulative Hotfix Patch 3 and below"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:hpe:aruba_clear_pass_policy_manager:*:*:*:*:*:*:*:*"
          ],
          "vendor": "hpe",
          "product": "aruba_clear_pass_policy_manager",
          "versions": [
            {
              "status": "affected",
              "version": "6.11x",
              "versionType": "custom",
              "lessThanOrEqual": "6.11.4"
            },
            {
              "status": "affected",
              "version": "6.10x",
              "lessThan": "6.10.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "6.9x",
              "lessThan": "6.9.13",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-25T18:17:32.050",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la interfaz de administración basada en web de ClearPass Policy Manager podría permitir que un atacante remoto no autenticado envíe notificaciones a ordenadores que ejecutan ClearPass OnGuard. Estas notificaciones pueden utilizarse para realizar phishing a los usuarios o engañarlos para que descarguen software malicioso."
    }
  ],
  "lastModified": "2026-06-17T06:25:38.103",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "124117E4-FE27-43AB-B5F5-B4EFCA767430",
              "versionEndExcluding": "6.9.13"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "84F5E56D-039C-47B0-827A-AFE34887DAD2",
              "versionEndExcluding": "6.10.8",
              "versionStartIncluding": "6.10.0"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "349AD8EE-ECFF-469B-80E6-0ABFDEF55A2C",
              "versionEndIncluding": "6.11.4",
              "versionStartIncluding": "6.11.0"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57C5BF92-A455-44E4-AE20-F9A1D790422D"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7962FD34-6A38-461A-8942-BCA227AF8AF9"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "435A3CE6-AB76-4F4F-B11F-71E0C7619A9A"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DB2448F-D014-4672-90A9-3BCC91096B93"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80F47102-7F9F-449F-91A1-76372AA7F3D4"
            },
            {
              "criteria": "cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F85708F3-CA05-472A-9B51-373D1AD14E9C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}