5.8
CVE-2023-43509
- EPSS 0.28%
- Veröffentlicht 25.10.2023 18:17:32
- Zuletzt bearbeitet 21.11.2024 08:24:11
- Quelle security-alert@hpe.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Clearpass Policy Manager Version < 6.9.13
Arubanetworks ≫ Clearpass Policy Manager Version >= 6.10.0 < 6.10.8
Arubanetworks ≫ Clearpass Policy Manager Version >= 6.11.0 <= 6.11.4
Arubanetworks ≫ Clearpass Policy Manager Version6.9.13 Update-
Arubanetworks ≫ Clearpass Policy Manager Version6.9.13 Updatecumulative_hotfix_patch_2
Arubanetworks ≫ Clearpass Policy Manager Version6.9.13 Updatecumulative_hotfix_patch_3
Arubanetworks ≫ Clearpass Policy Manager Version6.10.8 Update-
Arubanetworks ≫ Clearpass Policy Manager Version6.10.8 Updatecumulative_hotfix_patch_2
Arubanetworks ≫ Clearpass Policy Manager Version6.10.8 Updatecumulative_hotfix_patch_5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.506 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
security-alert@hpe.com | 5.8 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.