CVE-2024-26302

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager.
Configurations

No configuration.

History

21 Nov 2024, 09:02

Type Values Removed Values Added
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-001.txt - () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-001.txt -

05 Nov 2024, 15:35

Type Values Removed Values Added
CWE CWE-276
Summary
  • (es) Una vulnerabilidad en la interfaz de administración basada en web de ClearPass Policy Manager podría permitir que un atacante remoto autenticado con privilegios bajos acceda a información confidencial. Un exploit exitoso permite a un atacante recuperar información que podría usarse para obtener acceso adicional a los servicios de red compatibles con ClearPass Policy Manager.

27 Feb 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-27 23:15

Updated : 2024-11-21 09:02


NVD link : CVE-2024-26302

Mitre link : CVE-2024-26302

CVE.ORG link : CVE-2024-26302


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions