A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
References
Link | Resource |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt | Vendor Advisory |
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt - Vendor Advisory |
11 Sep 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
01 Nov 2023, 16:21
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt - Vendor Advisory | |
CPE | cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:-:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_2:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_2:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:-:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_3:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_5:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.8 |
First Time |
Arubanetworks clearpass Policy Manager
Arubanetworks |
25 Oct 2023, 18:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-25 18:17
Updated : 2024-11-21 08:24
NVD link : CVE-2023-43509
Mitre link : CVE-2023-43509
CVE.ORG link : CVE-2023-43509
JSON object : View
Products Affected
arubanetworks
- clearpass_policy_manager
CWE
NVD-CWE-noinfo
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')