CVE-2023-25591: Authenticated Information Disclosure in ClearPass Policy Manager Web-Based Management Interface
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further privileges on the ClearPass instance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25591?
CVE-2023-25591 is a vulnerability in the web-based management interface of ClearPass Policy Manager that could allow a remote attacker authenticated with low privileges to access sensitive information.
What is the severity of CVE-2023-25591?
The severity of CVE-2023-25591 is high.
How can an attacker exploit CVE-2023-25591?
A successful exploit of CVE-2023-25591 allows an attacker to retrieve information which could be used to potentially gain further privileges.
Which software versions are affected by CVE-2023-25591?
ClearPass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1 are affected by CVE-2023-25591.
How can I fix CVE-2023-25591?
To fix CVE-2023-25591, it is recommended to upgrade to a version that is not affected.