CVE-2024-26297: Command Injection
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26297?
CVE-2024-26297 is considered a critical vulnerability as it allows remote authenticated users to execute arbitrary commands as root on the underlying host.
How do I fix CVE-2024-26297?
To fix CVE-2024-26297, it is recommended to update Aruba ClearPass Policy Manager to the latest version available that addresses this vulnerability.
Who is affected by CVE-2024-26297?
Any organization using affected versions of Aruba ClearPass Policy Manager from versions 6.9.0 to 6.12.0 may be vulnerable to CVE-2024-26297.
Can CVE-2024-26297 be exploited remotely?
Yes, CVE-2024-26297 can be exploited remotely by authenticated users who have access to the web-based management interface.
What are the potential impacts of CVE-2024-26297?
The potential impacts of CVE-2024-26297 include unauthorized command execution and complete compromise of the underlying operating system.