Description
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-29536 | A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker to complete state-changing actions in the web-based management interface that should not be allowed by their current level of authorization on the platform. |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-02-27T15:02:53.121Z
Reserved: 2023-02-07T20:24:22.480Z
Link: CVE-2023-25594
Updated: 2024-08-02T11:25:19.296Z
Status : Modified
Published: 2023-03-22T06:15:10.337
Modified: 2025-02-27T15:15:37.313
Link: CVE-2023-25594
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD