CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2022-23696

High Severity|Arubanetworks
62
SVRS
8.8
CVSSv3
0.00415
EPSS
TAGSNo tags available
VECTOR STRING
CVSS:3.1AV:NAC:LPR:LUI:NS:UC:HI:HA:H
PUBLICATION DATE2022-09-20
LAST MODIFIED2025-05-28

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2022-23696, involves SQL injection flaws within the web-based management interface of Aruba ClearPass Policy Manager. It matters significantly because an authenticated remote attacker can exploit these flaws to execute SQL injection attacks. Such an attack could lead to the unauthorized retrieval and modification of sensitive information stored in the underlying database, potentially resulting in a complete compromise of the entire ClearPass Policy Manager cluster.
2. What are the CVSS score, severity level, and disclosure details?
  • CVSS Score: 8.8
  • Severity Level: High
  • Disclosure Details: The vulnerability was published on 2022-09-20 20:03:22 UTC and last modified on 2025-05-28 15:51:42 UTC.
3. Which products, vendors, systems, and versions are affected?
  • Vendor: Aruba
  • Product: ClearPass Policy Manager
  • Affected Systems: ClearPass Policy Manager cluster
  • Affected Versions:
    • 6.10.x: versions 6.10.6 and below
    • 6.9.x: versions 6.9.11 and below
4. What is the technical root cause and attack vector?
The technical root cause is SQL injection (CWE-89) vulnerabilities present in the web-based management interface of ClearPass Policy Manager. The attack vector is an authenticated remote attacker leveraging these vulnerabilities.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an authenticated remote attacker who can conduct SQL injection attacks through the ClearPass Policy Manager's web-based management interface. Successful exploitation allows the attacker to obtain and modify sensitive data within the underlying database, potentially leading to a full compromise of the ClearPass Policy Manager cluster.
6. What mitigation steps and patches are available?
Aruba has released upgrades for Aruba ClearPass Policy Manager that specifically address these security vulnerabilities. Users should upgrade their ClearPass Policy Manager instances to versions higher than the affected ones (i.e., above 6.10.6 for the 6.10.x branch and above 6.9.11 for the 6.9.x branch) to mitigate the risk.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the installed version of Aruba ClearPass Policy Manager. Any installations running version 6.10.6 or below within the 6.10.x series, or version 6.9.11 or below within the 6.9.x series, are considered vulnerable. Administrators should verify their current software versions against these thresholds.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is the Common Vulnerabilities and Exposures (CVE) entry: CVE-2022-23696. Additionally, Aruba has released advisories related to this vulnerability, which included information about the available upgrades.
11. What is the risk assessment and urgency level?
Risk Assessment: The risk associated with CVE-2022-23696 is assessed as High, indicated by a CVSS score of 8.8. The potential for an authenticated remote attacker to achieve complete compromise of the ClearPass Policy Manager cluster through SQL injection makes this a critical vulnerability. It could lead to significant data breaches, unauthorized modifications, and loss of control over the system.

Urgency Level: The urgency level for addressing this vulnerability is High. Given the high CVSS score, the ease of exploitation by an authenticated attacker, and the potential for complete system compromise, immediate patching and mitigation are strongly recommended to protect sensitive network access and policy management infrastructure.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

No news found for this CVE

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppArubanetworksclearpass_policy_manager
ReferenceLink
MITREhttps://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-013.txt
MISChttps://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-013.txt
MISChttps://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-013.txt
AF854A3A-2127-422B-91AE-364DA2661108https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-013.txt
[email protected]https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-013.txt
CWE IDCWE NameDescription
CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.