📦 Clearpass Policy Manager

by Arubanetworks

🔍 What is Clearpass Policy Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-25589

CRITICAL CVSS 9.8 Mar 22, 2023

An unauthenticated remote attacker can create arbitrary administrative users on ClearPass Policy Manager's web interface, leading to complete cluster compromise. This affects all organizations using v...

CVE-2022-23658

CRITICAL CVSS 10.0 May 16, 2022

CVE-2022-23658 is a critical remote authentication bypass vulnerability in Aruba ClearPass Policy Manager that allows attackers to bypass authentication mechanisms and gain unauthorized access to the ...

CVE-2022-23660

CRITICAL CVSS 10.0 May 16, 2022

This CVE describes a remote authentication bypass vulnerability in Aruba ClearPass Policy Manager that allows attackers to bypass authentication mechanisms without valid credentials. Affected organiza...

CVE-2022-23662

CRITICAL CVSS 9.1 May 16, 2022

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. An attacker with valid credentials can execute arbitrary commands on affected systems, pot...

CVE-2022-23664

CRITICAL CVSS 9.1 May 16, 2022

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can execute arbitrary commands on affected systems, poten...

CVE-2022-23666

CRITICAL CVSS 9.1 May 16, 2022

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can execute arbitrary commands on affected systems, poten...

CVE-2021-40996

CRITICAL CVSS 9.8 Oct 15, 2021

A remote authentication bypass vulnerability in Aruba ClearPass Policy Manager allows attackers to bypass authentication mechanisms and gain unauthorized access to the system. This affects ClearPass P...

CVE-2021-37736

CRITICAL CVSS 9.8 Oct 15, 2021

This CVE describes a remote authentication bypass vulnerability in Aruba ClearPass Policy Manager that allows attackers to bypass authentication mechanisms and gain unauthorized access. Affected organ...

CVE-2024-51771

HIGH CVSS 7.2 Dec 3, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary commands on HPE Aruba ClearPass Policy Manager systems through the web management interface. Organizations using affected ...

CVE-2024-41915

HIGH CVSS 7.2 Jul 30, 2024

An authenticated SQL injection vulnerability in ClearPass Policy Manager's web management interface allows attackers to execute arbitrary SQL commands. This could lead to data theft, modification, or ...

CVE-2024-26296

HIGH CVSS 7.2 Feb 27, 2024

This vulnerability in ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying operating system. This affects organizations using Aruba Cl...

CVE-2024-26298

HIGH CVSS 7.2 Feb 27, 2024

This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote users to execute arbitrary commands on the underlying host with root privileges. Attackers who gain authenticated acces...

CVE-2024-26294

HIGH CVSS 7.2 Feb 27, 2024

This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying operating system. It affects organizations using Clea...

CVE-2023-43507

HIGH CVSS 7.2 Oct 25, 2023

This SQL injection vulnerability in ClearPass Policy Manager's web management interface allows authenticated attackers to execute arbitrary SQL commands. Attackers could read, modify, or delete sensit...

CVE-2023-25591

HIGH CVSS 7.6 Mar 22, 2023

This vulnerability in ClearPass Policy Manager's web interface allows authenticated low-privilege users to access sensitive information. Attackers could use this information to potentially escalate pr...

CVE-2023-25593

HIGH CVSS 7.1 Mar 22, 2023

This vulnerability allows remote attackers to execute reflected cross-site scripting (XSS) attacks against users of the ClearPass Policy Manager web interface. Successful exploitation enables arbitrar...

CVE-2022-23669

HIGH CVSS 8.8 May 17, 2022

CVE-2022-23669 is a remote authorization bypass vulnerability in Aruba ClearPass Policy Manager that allows attackers to bypass authentication mechanisms and gain unauthorized access to the system. Th...

CVE-2022-23672

HIGH CVSS 7.2 May 17, 2022

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can execute arbitrary commands on affected systems, poten...

CVE-2021-40993

HIGH CVSS 8.1 Oct 15, 2021

This CVE describes a remote SQL injection vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary SQL commands on affected systems. Organizations running vulnerable ...

CVE-2021-40998

HIGH CVSS 7.2 Oct 15, 2021

This CVE describes a remote arbitrary command execution vulnerability in Aruba ClearPass Policy Manager. Attackers can execute arbitrary commands on affected systems, potentially gaining full control....

CVE-2021-40988

HIGH CVSS 7.2 Oct 15, 2021

This CVE describes a remote directory traversal vulnerability in Aruba ClearPass Policy Manager that allows attackers to access files outside the intended directory. Affected systems include ClearPass...

CVE-2021-40992

HIGH CVSS 7.2 Oct 15, 2021

A remote SQL injection vulnerability in Aruba ClearPass Policy Manager allows attackers to execute arbitrary SQL commands via crafted requests. This affects organizations running vulnerable versions o...

CVE-2021-37738

HIGH CVSS 7.5 Oct 15, 2021

CVE-2021-37738 is an information disclosure vulnerability in Aruba ClearPass Policy Manager that allows remote attackers to access sensitive information without authentication. Affected organizations ...

CVE-2021-40986

HIGH CVSS 7.2 Oct 15, 2021

This CVE describes a remote arbitrary command execution vulnerability in Aruba ClearPass Policy Manager. Attackers can execute arbitrary commands on affected systems without authentication, potentiall...

CVE-2021-40999

HIGH CVSS 7.2 Oct 15, 2021

This CVE allows remote attackers to execute arbitrary commands on Aruba ClearPass Policy Manager systems without authentication. It affects ClearPass Policy Manager versions 6.8.x, 6.9.x, and 6.10.x b...

CVE-2021-34609

HIGH CVSS 8.8 Jul 8, 2021

This CVE describes a remote SQL injection vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary SQL commands on the database. Affected organizations are those runn...

CVE-2021-34610

HIGH CVSS 7.2 Jul 8, 2021

CVE-2021-34610 is a remote command execution vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary commands on affected systems. This affects organizations using C...

CVE-2020-7123

HIGH CVSS 7.8 Apr 28, 2021

CVE-2020-7123 is a local privilege escalation vulnerability in Aruba ClearPass Policy Manager that allows authenticated local users to gain elevated privileges. This affects organizations running Clea...

CVE-2025-25039

MEDIUM CVSS 4.7 Feb 4, 2025

This vulnerability in HPE Aruba ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands on the underlying host with lower privileges. It affects organizations usin...

CVE-2025-23059

MEDIUM CVSS 6.8 Feb 4, 2025

This vulnerability in HPE Aruba ClearPass Policy Manager allows authenticated high-privilege attackers to access sensitive directories through the web management interface. It affects organizations us...

CVE-2024-51772

MEDIUM CVSS 6.4 Dec 3, 2024

An authenticated remote code execution vulnerability in ClearPass Policy Manager's web interface allows authenticated attackers to execute arbitrary commands on the underlying host. This affects organ...

CVE-2024-53672

MEDIUM CVSS 4.7 Dec 3, 2024

This vulnerability in ClearPass Policy Manager's web interface allows authenticated remote attackers to execute arbitrary commands on the host system with lower privileges. It affects organizations us...