First published: Tue Mar 14 2023(Updated: )
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Aruba Networking ClearPass Policy Manager | >=6.9.0<=6.9.13 | |
HPE Aruba Networking ClearPass Policy Manager | >=6.10.0<=6.10.8 | |
HPE Aruba Networking ClearPass Policy Manager | =6.11.0 | |
HPE Aruba Networking ClearPass Policy Manager | =6.11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2023-25596.
The affected software for this vulnerability is Arubanetworks Clearpass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, 6.11.0, and 6.11.1.
The severity level of CVE-2023-25596 is medium with a score of 4.9.
The CWE ID associated with this vulnerability is CWE-312.
The vulnerability can be exploited by an attacker with administrative privileges to access sensitive information in a cleartext format.