CVE-2025-37122: Hewlett Packard Enterprise HPE HPE Aruba Networking Clearpass Policy Manager
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browser in the context of the affected interface.
Affected products
- Hewlett Packard Enterprise HPE HPE Aruba Networking Clearpass Policy Manager: from 6.12.0, up to and including 6.12.5; from 6.11.0, up to and including 6.11.12
Published 2025-09-17. Last modified 2026-09-26.