5.5
CVE-2023-25595
- EPSS 0.04%
- Published 22.03.2023 06:15:10
- Last modified 27.02.2025 19:15:48
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard environment.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ Clearpass Policy Manager Version >= 6.9.0 <= 6.9.13
Arubanetworks ≫ Clearpass Policy Manager Version >= 6.10.0 <= 6.10.8
Arubanetworks ≫ Clearpass Policy Manager Version6.11.0
Arubanetworks ≫ Clearpass Policy Manager Version6.11.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.126 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
security-alert@hpe.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.