Impact
A flaw in the web-based management interface of Hewlett Packard Enterprise ClearPass Policy Manager lets an authenticated attacker run arbitrary operating-system commands, enabling remote code execution. The weakness is tied to OS command injection (CWE-78). The damage potential is to gain full control of the underlying host, compromising confidentiality, integrity, and availability of services running on it.
Affected Systems
All deployments of Hewlett Packard Enterprise ClearPass Policy Manager that expose the web interface are affected; no specific patch level is listed, so the risk applies across versions until a security update is applied.
Risk and Exploitability
The CVSS score of 7.2 demonstrates a high severity level, while the EPSS score of less than 1% suggests that widespread exploitation is unlikely at the present time. The vulnerability is not recorded in CISA's KEV catalog. Successful exploitation requires valid administrative credentials—once authenticated, the attacker can execute arbitrary commands through the exposed web interface, as inferred from the description of a web-based management interface flaw.
OpenCVE Enrichment