CVE-2022-23685 - CVE House
Back to Database
Status published Unknown CVE-2022-23685

A vulnerability in the ClearPass Policy Manager web-based management interface...

Vulnerability Description

A vulnerability in the ClearPass Policy Manager web-based management interface exists which exposes some endpoints to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against these endpoints if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23685

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Aruba ClearPass Policy Manager
Vulnerable Versions:
6.10.x: 6.10.6 and below, 6.9.x: 6.9.11 and below

Timeline

Official Publish: September 20th, 2022
Last Modified: May 27th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.