CVE-2025-25039: Arubanetworks Clearpass Policy Manager

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager (CPPM) allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a lower privileged user on the underlying operating system.

Affected products

  • Arubanetworks Clearpass Policy Manager: from 6.11.0, before 6.11.10 (fixed in 6.11.10); from 6.12.0, before 6.12.4 (fixed in 6.12.4)

Published 2025-02-04. Last modified 2026-06-17.