Known vulnerabilities in ClearPass Policy Manager

Software CPE: cpe:2.3:a:aruba_networks:clearpass_policy_manager:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 59
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ClearPass Policy Manager ClearPass Policy Manager is affected by 59 known vulnerabilities: 1 high, 16 medium, 42 low Critical High Medium Low

Vulnerabilities (59)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103673 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-25039
CWE-78 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103672 - Exposure of sensitive information to an unauthorized actor
CVE-2025-23060
CWE-200 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103671 - Exposure of sensitive information to an unauthorized actor
CVE-2025-23059
CWE-200 Low
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU103662 - Improper Access Control
CVE-2025-23058
CWE-284 Medium
No
No
6.11.10, 6.12.4 06.02.2025 SB2025020622
SB2025022013
#VU101878 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-53672
CWE-78 Low
No
No
6.11.10, 6.12.3 20.12.2024 SB2024122009
#VU101877 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-51773
CWE-79 Low
No
No
6.11.10, 6.12.3 20.12.2024 SB2024122009
#VU101876 - Deserialization of Untrusted Data
CVE-2024-51772
CWE-502 Low
No
No
6.11.10, 6.12.3 20.12.2024 SB2024122009
#VU101875 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-51771
CWE-94 Low
No
No
6.11.10, 6.12.3 20.12.2024 SB2024122009
#VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-7348
CWE-367 Low
No
No
6.11.10, 6.12.4 08.08.2024 SB2024080866
SB2024080954
SB2024080955
and 63 more
#VU94063 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2024-3596
CWE-327 Medium
Available
No
6.11.9, 6.12.2 10.07.2024 SB2024071018
SB2024071019
SB2024071020
and 114 more
#VU89892 - Exposure of sensitive information to an unauthorized actor
CVE-2024-26302
CWE-200 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89891 - Exposure of sensitive information to an unauthorized actor
CVE-2024-26301
CWE-200 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89890 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-26300
CWE-79 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89889 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-26299
CWE-79 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89884 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26294
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89885 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26295
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89886 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26296
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89887 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26297
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU89888 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-26298
CWE-78 Low
No
No
6.9.13 Hotfix Patch 7, 6.10.8 Hotfix Patch 8, 6.11.7, 6.12.1 29.05.2024 SB2024052938
SB2025041124
#VU82909 - Permissions, Privileges, and Access Controls
CVE-2023-43506
CWE-264 Low
No
No
6.9.13 Hotfix Q4 2023, 6.10.8 Hotfix Q4 2023, 6.11.5 08.11.2023 SB2023110812


Showing elements 1 - 20 out of 59