CVE-2024-51773

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*

History

07 Apr 2025, 15:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Arubanetworks clearpass Policy Manager
Arubanetworks
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US - Vendor Advisory
CPE cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*

03 Dec 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 21:15

Updated : 2025-04-07 15:02


NVD link : CVE-2024-51773

Mitre link : CVE-2024-51773


JSON object : View

Products Affected

arubanetworks

  • clearpass_policy_manager
CWE

No CWE.