Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-43539

Опубликовано: 05 янв. 2023
Источник: nvd
CVSS3: 5.7
CVSS3: 4.5
EPSS Низкий

Описание

A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Версия от 6.9.0 (включая) до 6.9.12 (исключая)
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Версия от 6.10.0 (включая) до 6.10.7 (исключая)

EPSS

Процентиль: 25%
0.00087
Низкий

5.7 Medium

CVSS3

4.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-200

Связанные уязвимости

CVSS3: 4.5
github
около 3 лет назад

A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the ClearPass Policy Manager cluster in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x: 6.10.7 and below and ClearPass Policy Manager 6.9.x: 6.9.12 and below.

EPSS

Процентиль: 25%
0.00087
Низкий

5.7 Medium

CVSS3

4.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-200