// For flags

CVE-2025-23060

Sensitive Data Exposure Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM)

Severity Score

6.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling data tampering.

*Credits: HPE Aruba Networking QA Team
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2025-01-10 CVE Reserved
  • 2025-02-04 CVE Published
  • 2025-02-04 CVE Updated
  • ---------- EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hewlett Packard Enterprise (HPE)
Search vendor "Hewlett Packard Enterprise (HPE)"
HPE Aruba Networking ClearPass Policy Manager
Search vendor "Hewlett Packard Enterprise (HPE)" for product "HPE Aruba Networking ClearPass Policy Manager"
>= 6.12.0 <= 6.12.3
Search vendor "Hewlett Packard Enterprise (HPE)" for product "HPE Aruba Networking ClearPass Policy Manager" and version " >= 6.12.0 <= 6.12.3"
en
Affected
Hewlett Packard Enterprise (HPE)
Search vendor "Hewlett Packard Enterprise (HPE)"
HPE Aruba Networking ClearPass Policy Manager
Search vendor "Hewlett Packard Enterprise (HPE)" for product "HPE Aruba Networking ClearPass Policy Manager"
>= 6.11.0 <= 6.11.9
Search vendor "Hewlett Packard Enterprise (HPE)" for product "HPE Aruba Networking ClearPass Policy Manager" and version " >= 6.11.0 <= 6.11.9"
en
Affected