« Volver al listado

Arubanetworks

Arubanetworks Clearpass Policy Manager: vulnerabilidades y CVE

Arubanetworks Clearpass Policy Manager tiene 136 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 17 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE136
Últimos 12 meses0
Críticas17
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2017-5638Crítica (9.8)100%⚠ Explotación activa11 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-25039Alta (8.8)0.65%—4 feb 2025
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit…
CVE-2025-23060Alta (8.1)0.23%—4 feb 2025
A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a…
CVE-2025-23059Media (4.9)0.60%—4 feb 2025
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an…
CVE-2025-23058Alta (8.1)0.72%—4 feb 2025
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions…
CVE-2024-53672Media (6.3)0.41%—3 dic 2024
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute…
CVE-2024-51773Media (5.4)0.27%—3 dic 2024
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful…
CVE-2024-51772Alta (8)0.46%—3 dic 2024
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow…
CVE-2024-51771Alta (8.8)0.76%—3 dic 2024
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation…
CVE-2024-5486Media (4.9)0.34%—30 jul 2024
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve…
CVE-2024-41916Media (4.9)0.36%—30 jul 2024
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve…
CVE-2024-41915Alta (8.8)0.55%—30 jul 2024
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker…
CVE-2024-26302Media (4.8)0.35%—27 feb 2024
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker…
CVE-2024-26301Media (6.5)0.52%—27 feb 2024
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker…
CVE-2024-26300Media (4.8)0.36%—27 feb 2024
A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A…
CVE-2024-26299Media (4.8)0.36%—27 feb 2024
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the…
CVE-2024-26298Alta (8.8)0.92%—27 feb 2024
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2024-26297Alta (8.8)0.92%—27 feb 2024
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2024-26296Alta (8.8)0.92%—27 feb 2024
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2024-26295Alta (8.8)0.93%—27 feb 2024
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2024-26294Alta (8.8)0.93%—27 feb 2024
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2023-43510Media (6.3)0.58%—25 oct 2023
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute…
CVE-2023-43509Media (5.8)0.57%—25 oct 2023
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications…
CVE-2023-43508Media (6.5)0.38%—25 oct 2023
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful…
CVE-2023-43507Alta (8.8)0.80%—25 oct 2023
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker…
CVE-2023-43506Alta (7.8)0.21%—25 oct 2023
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute…
CVE-2023-25596Media (4.9)0.33%—22 mar 2023
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve…
CVE-2023-25595Media (5.5)0.16%—22 mar 2023
A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability…
CVE-2023-25594Alta (8.8)0.46%—22 mar 2023
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance.…
CVE-2023-25593Media (6.1)0.47%—22 mar 2023
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful…
CVE-2023-25592Media (6.1)0.47%—22 mar 2023
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3
  3. T1190 Exploit Public-Facing Application2
  4. T1059.007 JavaScript1
  5. T1068 Exploitation for Privilege Escalation1
  6. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Arubanetworks