Arubanetworks
Arubanetworks Clearpass Policy Manager: vulnerabilidades y CVE
Arubanetworks Clearpass Policy Manager tiene 136 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 17 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE136
Últimos 12 meses0
Críticas17
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-5638 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 mar 2017 | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-25039 | Alta (8.8) | 0.65% | — | 4 feb 2025 | A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit… |
| CVE-2025-23060 | Alta (8.1) | 0.23% | — | 4 feb 2025 | A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a… |
| CVE-2025-23059 | Media (4.9) | 0.60% | — | 4 feb 2025 | A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an… |
| CVE-2025-23058 | Alta (8.1) | 0.72% | — | 4 feb 2025 | A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions… |
| CVE-2024-53672 | Media (6.3) | 0.41% | — | 3 dic 2024 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute… |
| CVE-2024-51773 | Media (5.4) | 0.27% | — | 3 dic 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful… |
| CVE-2024-51772 | Alta (8) | 0.46% | — | 3 dic 2024 | An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow… |
| CVE-2024-51771 | Alta (8.8) | 0.76% | — | 3 dic 2024 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation… |
| CVE-2024-5486 | Media (4.9) | 0.34% | — | 30 jul 2024 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve… |
| CVE-2024-41916 | Media (4.9) | 0.36% | — | 30 jul 2024 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve… |
| CVE-2024-41915 | Alta (8.8) | 0.55% | — | 30 jul 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker… |
| CVE-2024-26302 | Media (4.8) | 0.35% | — | 27 feb 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker… |
| CVE-2024-26301 | Media (6.5) | 0.52% | — | 27 feb 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker… |
| CVE-2024-26300 | Media (4.8) | 0.36% | — | 27 feb 2024 | A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A… |
| CVE-2024-26299 | Media (4.8) | 0.36% | — | 27 feb 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the… |
| CVE-2024-26298 | Alta (8.8) | 0.92% | — | 27 feb 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2024-26297 | Alta (8.8) | 0.92% | — | 27 feb 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2024-26296 | Alta (8.8) | 0.92% | — | 27 feb 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2024-26295 | Alta (8.8) | 0.93% | — | 27 feb 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2024-26294 | Alta (8.8) | 0.93% | — | 27 feb 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2023-43510 | Media (6.3) | 0.58% | — | 25 oct 2023 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute… |
| CVE-2023-43509 | Media (5.8) | 0.57% | — | 25 oct 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications… |
| CVE-2023-43508 | Media (6.5) | 0.38% | — | 25 oct 2023 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful… |
| CVE-2023-43507 | Alta (8.8) | 0.80% | — | 25 oct 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker… |
| CVE-2023-43506 | Alta (7.8) | 0.21% | — | 25 oct 2023 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute… |
| CVE-2023-25596 | Media (4.9) | 0.33% | — | 22 mar 2023 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve… |
| CVE-2023-25595 | Media (5.5) | 0.16% | — | 22 mar 2023 | A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability… |
| CVE-2023-25594 | Alta (8.8) | 0.46% | — | 22 mar 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance.… |
| CVE-2023-25593 | Media (6.1) | 0.47% | — | 22 mar 2023 | Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful… |
| CVE-2023-25592 | Media (6.1) | 0.47% | — | 22 mar 2023 | Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.