Impact
The vulnerability resides in the web‑based management interface of ClearPass Policy Manager and permits an authenticated remote attacker to run arbitrary operating‑system commands. Successful exploitation gives the attacker full control of the system, representing a code‑execution attack layered on a weakness in authentication handling.
Affected Systems
Hewlett Packard Enterprise’s ClearPass Policy Manager is the affected product. No specific version numbers are listed in the advisory, so all installations of the web interface remain at risk until patched.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. EPSS is not available and the issue is not on the CISA KEV list, suggesting limited documented exploitation. However, the requirement for authenticated access means attackers must compromise credentials first, but once obtained, they can execute arbitrary code remotely. The risk remains significant for organizations that expose the management interface to broader networks or use default credentials.
OpenCVE Enrichment