
CVE-2023-25591 – Authenticated Information Disclosure in ClearPass Policy Manager Web-Based Management Interface
https://notcve.org/view.php?id=CVE-2023-25591
14 Mar 2023 — A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further privileges on the ClearPass instance. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-003.txt • CWE-266: Incorrect Privilege Assignment •

CVE-2023-25590 – Local Privilege Escalation in ClearPass OnGuard Linux Agent
https://notcve.org/view.php?id=CVE-2023-25590
14 Mar 2023 — A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-003.txt • CWE-269: Improper Privilege Management •

CVE-2023-25589 – Unauthenticated Arbitrary User Creation Leads to Complete System Compromise
https://notcve.org/view.php?id=CVE-2023-25589
14 Mar 2023 — A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise. • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-003.txt • CWE-306: Missing Authentication for Critical Function •

CVE-2022-43540
https://notcve.org/view.php?id=CVE-2022-43540
03 Jan 2023 — A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Existe una vulnerabilidad en el agente ClearPass OnGuard macOS que permite a un atacante con acce... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-43539
https://notcve.org/view.php?id=CVE-2022-43539
03 Jan 2023 — A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Existe una v... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2022-43538
https://notcve.org/view.php?id=CVE-2022-43538
03 Jan 2023 — Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Las vulnerabilidades en la interfaz de admini... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2022-43537
https://notcve.org/view.php?id=CVE-2022-43537
03 Jan 2023 — Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Las vulnerabilidades en la interfaz de admini... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2022-43536
https://notcve.org/view.php?id=CVE-2022-43536
03 Jan 2023 — Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Las vulnerabilidades en la interfaz de admini... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2022-43535
https://notcve.org/view.php?id=CVE-2022-43535
03 Jan 2023 — A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with NT AUTHORITY\SYSTEM level privileges on the Windows instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Una vulnerabilidad en el agente de Windows ClearPass OnGuard podría permitir a usuario... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-269: Improper Privilege Management •

CVE-2022-43534
https://notcve.org/view.php?id=CVE-2022-43534
03 Jan 2023 — A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the Linux instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below. Una vulnerabilidad en el agente ClearPass OnGuard Linux podría permitir a usuarios malintencionados en una ... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-020.txt • CWE-269: Improper Privilege Management •