An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
History

Tue, 03 Dec 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Arubanetworks
Arubanetworks clearpass Policy Manager
Weaknesses CWE-77
CPEs cpe:2.3:a:arubanetworks:clearpass_policy_manager:-:*:*:*:*:*:*:*
Vendors & Products Arubanetworks
Arubanetworks clearpass Policy Manager
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 20:30:00 +0000

Type Values Removed Values Added
Description An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Title Authenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-12-03T21:54:52.951Z

Reserved: 2024-11-01T14:42:12.299Z

Link: CVE-2024-51772

cve-icon Vulnrichment

Updated: 2024-12-03T21:50:57.262Z

cve-icon NVD

Status : Received

Published: 2024-12-03T21:15:07.140

Modified: 2024-12-03T22:15:05.310

Link: CVE-2024-51772

cve-icon Redhat

No data.