CVE-2023-25593: Reflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based Management Interface
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25593?
CVE-2023-25593 is a vulnerability within the web-based management interface of ClearPass Policy Manager that allows a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
What is the severity of CVE-2023-25593?
CVE-2023-25593 has a severity rating of 6.1 (High).
How does CVE-2023-25593 affect Arubanetworks Clearpass Policy Manager?
CVE-2023-25593 affects Arubanetworks Clearpass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1.
How can a remote attacker exploit CVE-2023-25593?
A remote attacker can exploit CVE-2023-25593 by executing arbitrary script code in a victim's browser through a reflected cross-site scripting (XSS) attack.
Is there a fix available for CVE-2023-25593?
Yes, Arubanetworks has released a fix for this vulnerability. Please refer to the official Arubanetworks advisory for more information: [link to advisory].