CVE-2024-26299: XSS
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26299?
CVE-2024-26299 is rated as a medium severity vulnerability due to its ability to allow stored cross-site scripting attacks.
How do I fix CVE-2024-26299?
To fix CVE-2024-26299, apply the security patches provided by Hewlett Packard for the ClearPass Policy Manager software.
Who is affected by CVE-2024-26299?
CVE-2024-26299 affects users of the web-based management interface of Hewlett Packard ClearPass Policy Manager.
What are the potential impacts of CVE-2024-26299?
The potential impacts of CVE-2024-26299 include unauthorized execution of scripts, which can compromise the security of administrative functions in ClearPass Policy Manager.
Is CVE-2024-26299 a remote vulnerability?
Yes, CVE-2024-26299 is a remote vulnerability that requires an authenticated attacker to exploit it against an administrative user.