CVE-2023-25592: Reflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based Management Interface
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25592?
CVE-2023-25592 refers to vulnerabilities within the web-based management interface of ClearPass Policy Manager that could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack.
How does CVE-2023-25592 impact users?
CVE-2023-25592 allows an attacker to execute arbitrary script code in a victim's browser, potentially compromising their data and privacy.
Which versions of ClearPass Policy Manager are affected by CVE-2023-25592?
ClearPass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1 are affected by CVE-2023-25592.
What is the severity of CVE-2023-25592?
CVE-2023-25592 has a severity level of 6.1, which is classified as high.
How can users mitigate the risk of CVE-2023-25592?
Users can mitigate the risk of CVE-2023-25592 by updating ClearPass Policy Manager to a version that is not affected by the vulnerability, as recommended by the vendor.