Impact
An authentication bypass flaw exists in the API interface of ClearPass Policy Manager. The vulnerability allows a remote attacker to bypass existing authentication controls and access the API without credentials. Successful exploitation can lead to the disclosure of sensitive information stored or processed by the system.
Affected Systems
The affected product is Hewlett Packard Enterprise’s ClearPass Policy Manager. No specific version numbers are disclosed in the data, but any instance exposing the vulnerable API should be considered potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available, so the exploitation likelihood is unknown. The vulnerability is not currently listed in the CISA KEV catalog. An attacker would need to identify the exposed API endpoint and send unauthenticated requests; the vulnerability does not require local or privileged access, implying a broad attack surface over the network.
OpenCVE Enrichment