CVE-2023-25589: Unauthenticated Arbitrary User Creation Leads to Complete System Compromise
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25589?
CVE-2023-25589 is a vulnerability in the web-based management interface of ClearPass Policy Manager that allows an attacker to create arbitrary users on the platform.
Which software versions are affected by CVE-2023-25589?
ClearPass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1 are affected by CVE-2023-25589.
What is the severity of CVE-2023-25589?
CVE-2023-25589 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2023-25589?
An unauthenticated remote attacker can exploit CVE-2023-25589 to create arbitrary users on the ClearPass Policy Manager platform, potentially leading to total cluster compromise.
Is there a reference for more information about CVE-2023-25589?
Yes, you can find more information about CVE-2023-25589 at the following link: [Aruba Networks PSA](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-003.txt).