CVE-2023-43508: Authorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based Management Interface
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43508?
The severity of CVE-2023-43508 is medium with a severity value of 6.3.
What software is affected by CVE-2023-43508?
ClearPass Policy Manager version 6.9.13 up to 6.11.4 is affected by CVE-2023-43508.
How can an attacker exploit CVE-2023-43508?
An attacker with read-only privileges can exploit CVE-2023-43508 to perform actions that change the state of the ClearPass Policy Manager instance.
What is the fix for CVE-2023-43508?
To fix CVE-2023-43508, it is recommended to upgrade the ClearPass Policy Manager instance to a version that is not affected.
Are there any references for CVE-2023-43508?
Yes, you can find more information about CVE-2023-43508 at the following link: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt