Aruba Networks ClearPass OnGuard Linux是美国安移通(Aruba Networks)公司的一个解决方案模组。 Aruba Networks ClearPass OnGuard Linux存在安全漏洞,该漏洞源于可能允许Linux实例上的恶意用户将他们的用户权限提升到更高角色的权限,攻击者利用该漏洞可以以root权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | Aruba ClearPass Policy Manager | 6.11.1 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-25589 | 9.8 CRITICAL | Unauthenticated Arbitrary User Creation Leads to Complete System Compromise |
| CVE-2023-25591 | 7.6 HIGH | Authenticated Information Disclosure in ClearPass Policy Manager Web-Based Management Inte |
| CVE-2023-25593 | 7.1 HIGH | Reflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based |
| CVE-2023-25592 | 7.1 HIGH | Reflected Cross Site Scripting Vulnerabilities (XSS) in ClearPass Policy Manager Web-Based |
| CVE-2023-25594 | 6.3 MEDIUM | Authorization Bypass Leading to Privilege Escalation in ClearPass Policy Manager Web-Based |
| CVE-2023-25595 | 5.5 MEDIUM | Sensitive Information Disclosure in ClearPass OnGuard Ubuntu Agent |
| CVE-2023-25596 | 4.5 MEDIUM | Authenticated Sensitive Information Disclosure in ClearPass Policy Manager |
No comments yet