Description
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-45762 | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system. |
References
History
Mon, 07 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* |
Tue, 03 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks clearpass Policy Manager |
|
| Weaknesses | CWE-77 | |
| CPEs | cpe:2.3:a:arubanetworks:clearpass_policy_manager:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Arubanetworks
Arubanetworks clearpass Policy Manager |
|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the underlying operating system. | |
| Title | Authenticated Remote Code Execution (RCE) via OGNL Injection in HPE Aruba Networking ClearPass Web-Based Management Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2024-12-03T21:55:47.056Z
Reserved: 2024-11-01T14:42:12.299Z
Link: CVE-2024-51771
Updated: 2024-12-03T21:55:27.238Z
Status : Analyzed
Published: 2024-12-03T20:15:15.477
Modified: 2025-04-07T15:02:08.187
Link: CVE-2024-51771
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD