Impact
The vulnerability in the web‑based management interface of ClearPass Policy Manager allows an unauthenticated remote attacker to manipulate guest account settings. It is caused by missing authentication and access controls (CWE-287 and CWE-284), allowing the attacker to modify parameters without credentials. Successful exploitation can extend network access beyond policy limits, enabling prolonged unauthorized use of network resources.
Affected Systems
Hewlett Packard Enterprise ClearPass Policy Manager (CPPM) with a web‑based management interface. No specific version range is provided; any instance exposing the guest account management services is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no publicly known exploitation yet. The likely attack vector is the web interface, which is reachable from the network and does not require authentication. The attacker must send specially crafted requests to the account‑management endpoints, so while exploitation is feasible for a network‑aware attacker, the lack of credential needs raises the risk of unauthorized tampering.
OpenCVE Enrichment