CVE-2022-23664: Command Injection
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-23664?
CVE-2022-23664 is an authenticated remote command injection vulnerability discovered in Aruba ClearPass Policy Manager.
What versions of Aruba ClearPass Policy Manager are affected by CVE-2022-23664?
Aruba ClearPass Policy Manager versions 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below are affected by CVE-2022-23664.
What is the severity of CVE-2022-23664?
CVE-2022-23664 has a severity rating of 9.1 (critical).
How can I fix CVE-2022-23664 in Aruba ClearPass Policy Manager?
Aruba has released updates to ClearPass Policy Manager that address the security vulnerability. It is recommended to update to the latest version available.
Where can I find more information about CVE-2022-23664?
You can find more information about CVE-2022-23664 in the official Aruba Networks security advisory: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-007.txt