An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
References
Link | Resource |
---|---|
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Apr 2025, 15:03
Type | Values Removed | Values Added |
---|---|---|
First Time |
Arubanetworks
Arubanetworks clearpass Policy Manager |
|
CPE | cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* | |
References | () https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US - Vendor Advisory |
Information
Published : 2024-12-03 21:15
Updated : 2025-04-07 15:03
NVD link : CVE-2024-51772
Mitre link : CVE-2024-51772
CVE.ORG link : CVE-2024-51772
JSON object : View
Products Affected
arubanetworks
- clearpass_policy_manager
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')