ClearPass Policy Manager 的客户端软件中存在一个命令注入漏洞。成功利用该漏洞,攻击者可以通过向受影响的软件提供精心构造的输入,在受影响的主机上以较高权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | 6.14.0≤ 6.14.0 |
affected |
6.11.0≤ 6.11.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | 6.14.0 ~ 6.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79798 | 9.9 CRITICAL | Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Manageme |
| CVE-2026-76752 | 9.8 CRITICAL | Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Una |
| CVE-2026-79796 | 9.8 CRITICAL | Authentication Bypass Vulnerabilities in ClearPass Policy Manager |
| CVE-2026-79805 | 9.8 CRITICAL | Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modificat |
| CVE-2026-79801 | 9.8 CRITICAL | Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass P |
| CVE-2026-76753 | 9.8 CRITICAL | Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager |
| CVE-2026-76750 | 9.8 CRITICAL | Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web |
| CVE-2026-76751 | 9.8 CRITICAL | Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Una |
| CVE-2026-76754 | 9.8 CRITICAL | Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Po |
| CVE-2026-76742 | 9.8 CRITICAL | Authentication Bypass in the Web Management Interface of AOS-S |
| CVE-2026-76743 | 9.8 CRITICAL | Authentication Bypass Vulnerability in the Management Interface of AOS-S |
| CVE-2026-76744 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S |
| CVE-2026-76745 | 9.6 CRITICAL | Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Executio |
| CVE-2026-76746 | 9.3 CRITICAL | Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure i |
| CVE-2026-79794 | 9.1 CRITICAL | Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management |
| CVE-2026-76747 | 9.1 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S |
| CVE-2026-76748 | 8.8 HIGH | Authenticated Privilege Escalation Vulnerability in the API of AOS-S |
| CVE-2026-79799 | 8.8 HIGH | Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manage |
| CVE-2026-79803 | 8.8 HIGH | Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manage |
| CVE-2026-79797 | 8.8 HIGH | Improper Access Control in HPE Networking ClearPass Android Client Application |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet