Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3101 | A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 28 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arubanetworks
Arubanetworks clearpass Policy Manager |
|
| CPEs | cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arubanetworks
Arubanetworks clearpass Policy Manager |
Thu, 13 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1390 |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges. | |
| Title | Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management Interface | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2025-03-13T13:28:04.186Z
Reserved: 2025-01-10T16:27:25.924Z
Link: CVE-2025-23058
Updated: 2025-02-12T20:42:56.008Z
Status : Analyzed
Published: 2025-02-04T18:15:35.423
Modified: 2025-03-28T17:55:42.650
Link: CVE-2025-23058
No data.
OpenCVE Enrichment
No data.
EUVD