5
CVE-2013-2269
- EPSS 0.45%
- Published 01.10.2013 17:55:03
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows remote attackers to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ Clearpass Version5.0.1
Arubanetworks ≫ Clearpass Version5.1
Arubanetworks ≫ Clearpass Version5.2
Arubanetworks ≫ Clearpass Version6.0.1
Arubanetworks ≫ Clearpass Version6.0.2
Arubanetworks ≫ Clearpass Guest Version3.0
Arubanetworks ≫ Clearpass Guest Version3.1
Arubanetworks ≫ Clearpass Guest Version3.2
Arubanetworks ≫ Clearpass Guest Version3.3
Arubanetworks ≫ Clearpass Guest Version3.5
Arubanetworks ≫ Clearpass Guest Version3.7
Arubanetworks ≫ Clearpass Guest Version3.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.45% | 0.607 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|