CVE-2024-5486: Authenticated Sensitive Information Disclosure in ClearPass Policy Manager
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5486?
CVE-2024-5486 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2024-5486?
To fix CVE-2024-5486, it is recommended to upgrade ClearPass Policy Manager to versions 6.12.1 or higher, or to the latest version available.
Who is impacted by CVE-2024-5486?
CVE-2024-5486 affects users of ClearPass Policy Manager versions 6.11.0 to 6.11.8 and 6.12.0.
What type of access does CVE-2024-5486 allow to attackers?
CVE-2024-5486 allows attackers with administrative privileges to access sensitive information in cleartext format.
What kind of information can be retrieved due to CVE-2024-5486?
CVE-2024-5486 enables attackers to retrieve sensitive information that could be exploited for further unauthorized access.