Home

Description

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting (XSS) attack. Successful exploitation could enable a threat actor to perform any actions the user is authorized to do, including accessing the user's data and altering information within the user's permissions. This could lead to data modification, deletion, or theft, including unauthorized access to files, file deletion, or the theft of session cookies, which an attacker could use to hijack a user's session.

PUBLISHED Reserved 2024-11-01 | Published 2024-12-03 | Updated 2024-12-03 | Assigner hpe




MEDIUM: 4.8CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Product status

Default status
unaffected

6.12.0 (semver)
affected

6.11.0 (semver)
affected

Credits

Pear1y finder

References

support.hpe.com/...y?docId=hpesbnw04761en_us&docLocale=en_US

cve.org (CVE-2024-51773)

nvd.nist.gov (CVE-2024-51773)

Download JSON