First published: Tue Oct 24 2023(Updated: )
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Clearpass Policy Manager | <6.9.13 | |
Arubanetworks Clearpass Policy Manager | >=6.10.0<6.10.8 | |
Arubanetworks Clearpass Policy Manager | >=6.11.0<=6.11.4 | |
Arubanetworks Clearpass Policy Manager | =6.9.13 | |
Arubanetworks Clearpass Policy Manager | =6.9.13-cumulative_hotfix_patch_2 | |
Arubanetworks Clearpass Policy Manager | =6.9.13-cumulative_hotfix_patch_3 | |
Arubanetworks Clearpass Policy Manager | =6.10.8 | |
Arubanetworks Clearpass Policy Manager | =6.10.8-cumulative_hotfix_patch_2 | |
Arubanetworks Clearpass Policy Manager | =6.10.8-cumulative_hotfix_patch_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-43509 is medium.
CVE-2023-43509 affects ClearPass Policy Manager versions up to 6.11.4.
An attacker can exploit CVE-2023-43509 by sending notifications to computers running ClearPass OnGuard to phish users or trick them into downloading malicious software.
Yes, upgrading to a version higher than 6.11.4 resolves the vulnerability.
You can find more information about CVE-2023-43509 in the Aruba Networks security advisory: https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt