CVE-2025-23058: Arubanetworks Clearpass Policy Manager
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
Affected products
- Arubanetworks Clearpass Policy Manager: from 6.11.0, before 6.11.10 (fixed in 6.11.10); from 6.12.0, before 6.12.4 (fixed in 6.12.4)
Published 2025-02-04. Last modified 2026-06-17.