CVE Vulnerabilities

CVE-2023-43506

Published: Oct 25, 2023 | Modified: Nov 01, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.

Affected Software

Name Vendor Start Version End Version
Clearpass_policy_manager Arubanetworks * 6.9.13 (excluding)
Clearpass_policy_manager Arubanetworks 6.10.0 (including) 6.10.8 (excluding)
Clearpass_policy_manager Arubanetworks 6.11.0 (including) 6.11.4 (including)
Clearpass_policy_manager Arubanetworks 6.9.13 (including) 6.9.13 (including)
Clearpass_policy_manager Arubanetworks 6.9.13-cumulative_hotfix_patch_2 (including) 6.9.13-cumulative_hotfix_patch_2 (including)
Clearpass_policy_manager Arubanetworks 6.9.13-cumulative_hotfix_patch_3 (including) 6.9.13-cumulative_hotfix_patch_3 (including)
Clearpass_policy_manager Arubanetworks 6.10.8 (including) 6.10.8 (including)
Clearpass_policy_manager Arubanetworks 6.10.8-cumulative_hotfix_patch_2 (including) 6.10.8-cumulative_hotfix_patch_2 (including)
Clearpass_policy_manager Arubanetworks 6.10.8-cumulative_hotfix_patch_5 (including) 6.10.8-cumulative_hotfix_patch_5 (including)

References