CVE-2024-51772

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*

History

07 Apr 2025, 15:03

Type Values Removed Values Added
First Time Arubanetworks
Arubanetworks clearpass Policy Manager
CPE cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:*
References () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US - () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US - Vendor Advisory

Information

Published : 2024-12-03 21:15

Updated : 2025-04-07 15:03


NVD link : CVE-2024-51772

Mitre link : CVE-2024-51772

CVE.ORG link : CVE-2024-51772


JSON object : View

Products Affected

arubanetworks

  • clearpass_policy_manager
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')