CVE-2025-23060: Arubanetworks Clearpass Policy Manager

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling data tampering.

Affected products

  • Arubanetworks Clearpass Policy Manager: from 6.11.0, before 6.11.10 (fixed in 6.11.10); from 6.12.0, before 6.12.4 (fixed in 6.12.4)

Published 2025-02-04. Last modified 2026-06-17.