A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
References
Link | Resource |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
01 Nov 2023, 16:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Arubanetworks
Arubanetworks clearpass Policy Manager |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.8 |
CWE | NVD-CWE-noinfo | |
References | (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt - Vendor Advisory | |
CPE | cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:-:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:-:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_3:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.9.13:cumulative_hotfix_patch_2:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_5:*:*:*:*:*:* cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.10.8:cumulative_hotfix_patch_2:*:*:*:*:*:* |
25 Oct 2023, 18:17
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-25 18:17
Updated : 2024-09-11 18:35
NVD link : CVE-2023-43509
Mitre link : CVE-2023-43509
JSON object : View
Products Affected
arubanetworks
- clearpass_policy_manager
CWE