CVE-2025-23058: Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management Interface
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23058?
CVE-2025-23058 is classified as a high-severity vulnerability due to its potential for unauthorized access and execution of restricted functions.
How do I fix CVE-2025-23058?
To fix CVE-2025-23058, ensure that you apply the latest security patches and updates provided by Hewlett Packard for ClearPass Policy Manager.
What are the risks associated with CVE-2025-23058?
The risks associated with CVE-2025-23058 include unauthorized data access and the ability to execute administrative functions by low-privileged users.
Who is affected by CVE-2025-23058?
CVE-2025-23058 affects users of Hewlett Packard ClearPass Policy Manager who have low-privileged accounts.
What types of attacks can be executed using CVE-2025-23058?
Using CVE-2025-23058, an authenticated attacker can exploit the vulnerability to gain unauthorized access and perform actions typically reserved for administrators.