CVE-2023-25590: Local Privilege Escalation in ClearPass OnGuard Linux Agent
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25590?
CVE-2023-25590 is a vulnerability in the ClearPass OnGuard Linux agent that allows malicious users on a Linux instance to elevate their user privileges and execute arbitrary code with root level privileges.
How does CVE-2023-25590 affect Arubanetworks Clearpass Policy Manager?
Arubanetworks Clearpass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1 are affected by CVE-2023-25590.
What is the severity of CVE-2023-25590?
CVE-2023-25590 has a severity score of 7.8, which is considered high.
How can I fix CVE-2023-25590?
Apply the necessary patches and updates provided by Arubanetworks to fix CVE-2023-25590.
Where can I find more information about CVE-2023-25590?
You can find more information about CVE-2023-25590 in the advisory published by Arubanetworks at the following link: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-003.txt