Impact
A flaw in the ClearPass Policy Manager web interface permits an authenticated attacker to write arbitrary files, which can be leveraged to run arbitrary commands on the host operating system. This results in total loss of control over the affected system, enabling execution of malicious code. The weakness is rooted in inadequate input validation and insufficient privilege checks, allowing attackers to influence file system operations beyond their authorization.
Affected Systems
Hewlett Packard Enterprise’s ClearPass Policy Manager is vulnerable. No specific version ranges are listed, meaning all current releases may be affected until the vendor publishes a fix.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. Because the vulnerability requires authentication, an attacker must possess valid credentials, but many administrators grant broad access. The EPSS score is not available, suggesting limited data on active exploitation. The vulnerability is not included in CISA’s KEV catalog, but the potential for remote code execution warrants immediate attention.
OpenCVE Enrichment