CVE-2023-43510: Authenticated Remote Command Injection in ClearPass Policy Manager Web-Based Management Interface Leading to Partial System Compromise
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the underlying operating system leading to partial system compromise.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43510?
CVE-2023-43510 is a vulnerability in the ClearPass Policy Manager web-based management interface that allows remote authenticated users to run arbitrary commands on the underlying host.
Which software is affected by CVE-2023-43510?
The ClearPass Policy Manager software versions 6.9.13, 6.10.0 to 6.10.8, and 6.11.0 to 6.11.4 are affected by CVE-2023-43510.
What is the severity of CVE-2023-43510?
The severity of CVE-2023-43510 is medium with a CVSS score of 6.3.
How can an attacker exploit CVE-2023-43510?
An attacker with remote authenticated access can exploit CVE-2023-43510 to execute arbitrary commands on the underlying operating system.
Is there a fix for CVE-2023-43510?
Yes, updating the ClearPass Policy Manager software to a version that is not affected by CVE-2023-43510 will fix the vulnerability.