CVE-2024-26302: Medium severity aruba clearpass policy manager vulnerability
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26302?
CVE-2024-26302 has been assigned a medium severity rating due to its potential impact on sensitive information access.
How do I fix CVE-2024-26302?
To fix CVE-2024-26302, upgrade to the latest version of ClearPass Policy Manager provided by Aruba Networks.
What types of information can be accessed through CVE-2024-26302?
CVE-2024-26302 allows access to sensitive information that authenticated low-privileged users might exploit to gain further access.
Who is affected by CVE-2024-26302?
CVE-2024-26302 affects users of the web-based management interface of Aruba Networks ClearPass Policy Manager.
Can CVE-2024-26302 be exploited remotely?
Yes, CVE-2024-26302 can be exploited remotely by an authenticated user with low privileges.