Impact
The vulnerability allows an attacker who already has physical or local access to a system running the ClearPass client software to read sensitive information that the application handles. Because the flaw is not remotely exploitable, it does not grant broader network reach but can compromise local credentials, configuration data, or other privileged details that could assist in a larger compromise. The weakness corresponds to an information exposure flaw, where data that should remain confidential is inadvertently revealed to a local user.
Affected Systems
Hewlett Packard Enterprise’s ClearPass Policy Manager client software is affected. No specific version numbers are disclosed in the available data, so all releases of the client should be reviewed against vendor advisories to determine the applicability of this issue.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and at the time of analysis no EPSS score is provided, suggesting that historical exploitation activity is not known. The vulnerability is not listed in CISA’s KEV catalog, which implies it has not yet been observed as part of a widespread exploitation campaign. The likely attack vector involves local physical or administrative access; an attacker would need to be able to log into or otherwise access the target system to read the exposed data. Because the flaw requires local access, the overall risk is limited to environments where compromised physical or user accounts are a concern. Nonetheless, the exposure of sensitive information can enable further attacks, such as credential theft or lateral movement, if an adversary applies the disclosed data in a broader campaign.
OpenCVE Enrichment