ClearPass Policy Manager OnGuard 代理程序中存在一个任意文件写入漏洞,如果满足某些不受攻击者控制的前提条件,允许本地实例上的恶意用户提升其用户权限。成功利用此漏洞可使本地攻击者在受影响系统上以高权限执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | 6.14.0≤ 6.14.0 |
affected |
6.11.0≤ 6.11.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | ClearPass Policy Manager (CPPM) | 6.14.0 ~ 6.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79798 | 9.9 CRITICAL | Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Manageme |
| CVE-2026-76744 | 9.8 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-S |
| CVE-2026-76743 | 9.8 CRITICAL | Authentication Bypass Vulnerability in the Management Interface of AOS-S |
| CVE-2026-76742 | 9.8 CRITICAL | Authentication Bypass in the Web Management Interface of AOS-S |
| CVE-2026-79796 | 9.8 CRITICAL | Authentication Bypass Vulnerabilities in ClearPass Policy Manager |
| CVE-2026-79801 | 9.8 CRITICAL | Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass P |
| CVE-2026-76754 | 9.8 CRITICAL | Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Po |
| CVE-2026-76751 | 9.8 CRITICAL | Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Una |
| CVE-2026-76750 | 9.8 CRITICAL | Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web |
| CVE-2026-76752 | 9.8 CRITICAL | Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Una |
| CVE-2026-76753 | 9.8 CRITICAL | Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager |
| CVE-2026-79805 | 9.8 CRITICAL | Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modificat |
| CVE-2026-76745 | 9.6 CRITICAL | Unauthenticated Adjacent Memory Corruption Vulnerabilities Leading to Remote Code Executio |
| CVE-2026-76746 | 9.3 CRITICAL | Unauthenticated Adjacent Buffer Overflow Vulnerability Leading to Information Disclosure i |
| CVE-2026-76747 | 9.1 CRITICAL | Unauthenticated Buffer Overflow Vulnerabilities lead to Information Disclosure in AOS-S |
| CVE-2026-79794 | 9.1 CRITICAL | Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management |
| CVE-2026-79797 | 8.8 HIGH | Improper Access Control in HPE Networking ClearPass Android Client Application |
| CVE-2026-79802 | 8.8 HIGH | Command Injection Vulnerability in the ClearPass Policy Manager Client Software |
| CVE-2026-79800 | 8.8 HIGH | Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Pol |
| CVE-2026-76748 | 8.8 HIGH | Authenticated Privilege Escalation Vulnerability in the API of AOS-S |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet