CVE-2023-43509
Unauthenticated Endpoint Allows Sending Arbitrary OnGuard Notifications
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
Una vulnerabilidad en la interfaz de administración basada en web de ClearPass Policy Manager podría permitir que un atacante remoto no autenticado envíe notificaciones a ordenadores que ejecutan ClearPass OnGuard. Estas notificaciones pueden utilizarse para realizar phishing a los usuarios o engañarlos para que descarguen software malicioso.
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-09-19 CVE Reserved
- 2023-10-24 CVE Published
- 2024-09-11 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt | 2023-11-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | < 6.9.13 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " < 6.9.13" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | >= 6.10.0 < 6.10.8 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " >= 6.10.0 < 6.10.8" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | >= 6.11.0 <= 6.11.4 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version " >= 6.11.0 <= 6.11.4" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.9.13 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.9.13" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.9.13 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.9.13" | cumulative_hotfix_patch_2 |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.9.13 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.9.13" | cumulative_hotfix_patch_3 |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.10.8 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.10.8" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.10.8 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.10.8" | cumulative_hotfix_patch_2 |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Clearpass Policy Manager Search vendor "Arubanetworks" for product "Clearpass Policy Manager" | 6.10.8 Search vendor "Arubanetworks" for product "Clearpass Policy Manager" and version "6.10.8" | cumulative_hotfix_patch_5 |
Affected
|