CVE-2025-25039

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*

History

28 Mar 2025, 17:37

Type Values Removed Values Added
First Time Arubanetworks clearpass Policy Manager
Arubanetworks
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04784en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04784en_us&docLocale=en_US - Vendor Advisory
CPE cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

04 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-04 19:15

Updated : 2025-03-28 17:37


NVD link : CVE-2025-25039

Mitre link : CVE-2025-25039


JSON object : View

Products Affected

arubanetworks

  • clearpass_policy_manager
CWE

No CWE.