CVE-2022-37883: Command Injection
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address these security vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37883?
CVE-2022-37883 is a vulnerability in the ClearPass Policy Manager web-based management interface that allows remote authenticated users to run arbitrary commands on the underlying host.
How does CVE-2022-37883 impact ClearPass Policy Manager?
CVE-2022-37883 allows an attacker to execute arbitrary commands as root on the underlying operating system, leading to complete compromise of the system.
Which versions of ClearPass Policy Manager are affected by CVE-2022-37883?
ClearPass Policy Manager versions between 6.9.0 and 6.9.12, and versions between 6.10.0 and 6.10.7 are affected by CVE-2022-37883.
What is the severity of CVE-2022-37883?
CVE-2022-37883 has a severity rating of 7.2 out of 10, indicating a high severity vulnerability.
How can I mitigate the vulnerability CVE-2022-37883?
To mitigate CVE-2022-37883, it is recommended to update ClearPass Policy Manager to a version that is not affected by the vulnerability.