iTnews Asia
  • Home
  • News
  • Security

Aruba Networks patches ClearPass bugs

Aruba Networks patches ClearPass bugs

Three software branches fixed.

By Richard Chirgwin on Mar 15, 2023 10:14AM

Aruba Networks has disclosed a collection of patches covering eight vulnerabilities in its ClearPass Policy Manager software.

The software provides unified network access enforcement across wireless, wired and VPN networks.

Leading the list is a bug found by New Zealander pentester Daniel Jensen.

CVE-2023-25589 (CVSS score 9.8) is a bug in the ClearPass policy manager’s web-based management interface.

Unauthenticated attackers could achieve “total cluster compromise” by creating arbitrary users on the platform, Aruba said.

There are also four bugs rated high-severity. 

The OnGuard Linux agent has a local privilege escalation bug rated 7.8, CVE-2023-25590. 

A successful attacker on a Linux instance could execute arbitrary code with root privilege on the Linux instance.

Luke Young reported the vulnerability via the company’s Bugcrowd bounty program.

Under CVE-2023-25591, an attacker who can authenticate with low privileges can take advantage of a bug in the policy manager’s web-based interface, potentially retrieving information to gain further privileges.

This bug was also attributed to Luke Young.

Two reflected cross site scripting bugs, CVE-2023-25592 and CVE-2023-25593, allow an attacker to execute arbitrary script code in a victim’s browser.

The remaining three vulnerabilities patched today are rated medium severity.

The affected software versions are ClearPass Policy Manager 6.11.1 and below, 6.10.8 and blow, and 6.913 and below, and fixed versions are available.

The full advisory is here.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
aruba networks clearpass security

Related Articles

  • Proofpoint CEO: A tool-based approach for cybersecurity is impractical
  • Akamai: AI-security is both a security imperative and an economic necessity
  • The real-life Tom & Jerry chase
  • How can we bolster our resilience against AI-enabled e-mail attacks?
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

Proofpoint CEO: A tool-based approach for cybersecurity is impractical

The real-life Tom & Jerry chase

The real-life Tom & Jerry chase

How can we bolster our resilience against AI-enabled e-mail attacks?

How can we bolster our resilience against AI-enabled e-mail attacks?

Akamai: AI-security is both a security imperative and an economic necessity

Akamai: AI-security is both a security imperative and an economic necessity

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.