First published: Tue Oct 24 2023(Updated: )
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Linux Linux kernel | ||
Any of | ||
Arubanetworks Clearpass Policy Manager | <6.9.13 | |
Arubanetworks Clearpass Policy Manager | >=6.10.0<6.10.8 | |
Arubanetworks Clearpass Policy Manager | >=6.11.0<=6.11.4 | |
Arubanetworks Clearpass Policy Manager | =6.9.13 | |
Arubanetworks Clearpass Policy Manager | =6.9.13-cumulative_hotfix_patch_2 | |
Arubanetworks Clearpass Policy Manager | =6.9.13-cumulative_hotfix_patch_3 | |
Arubanetworks Clearpass Policy Manager | =6.10.8 | |
Arubanetworks Clearpass Policy Manager | =6.10.8-cumulative_hotfix_patch_2 | |
Arubanetworks Clearpass Policy Manager | =6.10.8-cumulative_hotfix_patch_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43506 is a vulnerability in the ClearPass OnGuard Linux agent that allows malicious users on a Linux instance to elevate their user privileges and execute arbitrary code with root level privileges.
CVE-2023-43506 affects Arubanetworks Clearpass Policy Manager versions up to 6.9.13, versions between 6.10.0 and 6.10.8, and versions between 6.11.0 and 6.11.4.
CVE-2023-43506 has a severity value of 7.8, which is considered high.
To fix CVE-2023-43506 in Arubanetworks Clearpass Policy Manager, you should update to a version higher than 6.11.4.
You can find more information about CVE-2023-43506 in the advisory released by Aruba Networks: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt