Impact
An authenticated attacker who can access the ClearPass Policy Manager web interface can read directory information and execute arbitrary commands on the underlying operating system. This allows full compromise of the host with unrestricted execution of malicious code. The weakness involves OS command injection (CWE-78).
Affected Systems
Hewlett Packard Enterprise’s ClearPass Policy Manager (CPPM) is affected. No specific version ranges are listed, implying that all current releases remain vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the near term. Because authentication is required, attackers must have valid credentials, which many administrators provide. Although it is not listed in CISA’s KEV catalog, the potential for remote code execution makes it a high‑priority target for remediation.
OpenCVE Enrichment