CVE-2024-26301: Medium severity aruba clearpass policy manager vulnerability
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26301?
CVE-2024-26301 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-26301?
To fix CVE-2024-26301, update the ClearPass Policy Manager to version 6.11.7 or later.
What systems are affected by CVE-2024-26301?
CVE-2024-26301 affects Aruba ClearPass Policy Manager versions 6.9.0 to 6.9.13, 6.10.0 to 6.10.8, and 6.11.0 to 6.11.6.
Can CVE-2024-26301 be exploited remotely?
Yes, CVE-2024-26301 can be exploited remotely by an authenticated attacker with low privileges.
What type of information can be accessed via CVE-2024-26301?
CVE-2024-26301 may allow access to sensitive information that could be used to gain further access to the system.