CVE-2022-23662

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/05/2022
Last modified:
03/11/2022

Description

A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* 6.8.9 (excluding)
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* 6.9.0 (including) 6.9.10 (excluding)
cpe:2.3:a:arubanetworks:clearpass_policy_manager:*:*:*:*:*:*:*:* 6.10.0 (including) 6.10.5 (excluding)
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:-:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix1:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:clearpass_policy_manager:6.8.9:hotfix2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools