VDB
CVE-2022-23671
CVE-2022-23671
PUBLISHED
CVSS 7.5 HIGH
A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
EPSS 0.42% · 62.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.42%
62.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Aruba ClearPass Policy Manager | 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below |
| arubanetworks | clearpass_policy_manager | 6.8.0, 6.9.0, 6.10.0 |
Exploit Intelligence
Timeline
- May 5, 2022 CVE Published
- May 18, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Aug 25, 2022 EPSS Score
- Oct 13, 2022 EPSS Score
- Dec 1, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- Jun 15, 2023 EPSS Score
- Aug 3, 2023 EPSS Score