CVE-2024-5486
Last modified
CVE-2024-5486 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Clearpass Policy Manager | >= 6.11, <= 6.11.8 |
| Arubanetworks | Clearpass Policy Manager | 6.12.0 |
| Arubanetworks | Clearpass Policy Manager | 6.12.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5486?
How severe is CVE-2024-5486?
How do I fix CVE-2024-5486?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-54849An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attack…5.9
- CVE-2024-5485The SureTriggers – Connect All Your Plugins, Apps, Tools & A…6.4
- CVE-2024-54851Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (C…8.8
- CVE-2024-54852When LDAP connection is activated in Teedy versions between …9.8
- CVE-2024-54853A Stored Cross-Site Scripting (XSS) vulnerability was identi…5.4
- CVE-2024-54855fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovere…6.4
- CVE-2024-5487Zohocorp ManageEngine ADAudit Plus versions below 8110 are v…8.8
- CVE-2024-54879SeaCMS V13.1 is vulnerable to Incorrect Access Control. A lo…9.1
- CVE-2024-5488The SEOPress WordPress plugin before 7.9 does not properly …9.8
- CVE-2024-54880SeaCMS V13.1 is vulnerable to Incorrect Access Control. A lo…9.1
- CVE-2024-54887TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier…8
- CVE-2024-5489The Wbcom Designs – Custom Font Uploader plugin for WordPres…4.3
Are you affected by CVE-2024-5486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
