A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
References
Link | Resource |
---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-016.txt | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Sep 2024, 18:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-25 18:17
Updated : 2024-09-11 18:35
NVD link : CVE-2023-43509
Mitre link : CVE-2023-43509
CVE.ORG link : CVE-2023-43509
JSON object : View
Products Affected
arubanetworks
- clearpass_policy_manager
CWE
NVD-CWE-noinfo
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')