{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "High"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Networking has released updates to the ClearPass Policy Manager (CPPM) to address multiple vulnerabilities.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect HPE Networking ClearPass Policy Manager running the following software versions unless specifically noted otherwise in the details section:\n\nHPE Networking ClearPass Policy Manager\n - 6.12.x: ClearPass 6.12.8 and below\n - 6.11.x: ClearPass 6.11.14 and below\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "HPE Networking is not aware of any public discussion or exploit code targeting these specific vulnerabilities as of the release date of this advisory.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at:\nhttp://www.hpe.com/support/security-response-policy\n \nFor reporting NEW HPE Networking security issues, email can be sent to networking-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: networking-sirt(at)hpe.com - For further details please see http://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Networking products. The HPE Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported. A security vulnerability is defined as any weakness in a product that allows an attacker to compromise the confidentiality, integrity, or availability of a product, customer infrastructure, or IT system through an HPE Networking product in that environment.",
      "name": "HPE Networking",
      "namespace": "http://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Aruba Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "summary": "HPE Aruba Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Multiple Vulnerabilities in HPE Networking ClearPass Policy Manager (CPPM)",
    "tracking": {
      "current_release_date": "2026-09-09T16:00:00.000Z",
      "generator": {
        "date": "2026-09-09T18:25:05.012Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.12"
        }
      },
      "id": "HPESBNW05130",
      "initial_release_date": "2026-09-09T16:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-09-09T16:00:00.000Z",
          "number": "1",
          "summary": "Initial release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "6.14.0",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager",
                  "product_id": "CPPM-6.14.0"
                }
              },
              {
                "category": "product_version",
                "name": "6.12.8-HF",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager",
                  "product_id": "CPPM-6.12.8-HF"
                }
              },
              {
                "category": "product_version",
                "name": "6.11.15",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager",
                  "product_id": "CPPM-6.11.15"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=6.12.0|<=6.12.8",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager",
                  "product_id": ">=6.12.0|<=6.12.8"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=6.11.0|<=6.11.14",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager",
                  "product_id": ">=6.11.0|<=6.11.14"
                }
              }
            ],
            "category": "product_name",
            "name": "ClearPass Policy Manager (CPPM)"
          }
        ],
        "category": "vendor",
        "name": "HPE Aruba Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "promasu"
          ],
          "summary": "This vulnerability was discovered and reported by promasu."
        }
      ],
      "cve": "CVE-2026-73786",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-55",
          "title": "Internal References"
        },
        {
          "category": "other",
          "text": "This vulnerability does not impact 6.12.x",
          "title": "Note"
        }
      ],
      "product_status": {
        "fixed": [
          "CPPM-6.11.15",
          "CPPM-6.14.0"
        ],
        "known_affected": [
          ">=6.11.0|<=6.11.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Networking ClearPass Policy Manager to one of the following versions:\n\nHPE Networking ClearPass Policy Manager\n - 6.14.x: ClearPass 6.14.0 and above\n - 6.12.x: ClearPass 6.12.8-HF and above\n - 6.11.x: ClearPass 6.11.15 and above\n\nNOTE: Customers running HPE Networking ClearPass Policy Manager 6.12.x are encouraged to upgrade to a supported software branch for complete remediation.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at\nhttps://networkingsupport.hpe.com/home.",
          "product_ids": [
            "CPPM-6.11.15",
            "CPPM-6.14.0"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services Aruba Networking for any configuration assistance if needed.",
          "product_ids": [
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.5,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.5,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "title": "Unauthenticated Network-Based Denial of Service in CPPM systems"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Luke Young (@bored_engineer)"
          ],
          "summary": "This vulnerability was discovered and reported by Luke Young (@bored_engineer)."
        }
      ],
      "cve": "CVE-2026-73787",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-48",
          "title": "Internal References"
        },
        {
          "category": "other",
          "text": "This vulnerability does not impact 6.12.x",
          "title": "Note"
        }
      ],
      "product_status": {
        "fixed": [
          "CPPM-6.11.15",
          "CPPM-6.14.0"
        ],
        "known_affected": [
          ">=6.11.0|<=6.11.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Networking ClearPass Policy Manager to one of the following versions:\n\nHPE Networking ClearPass Policy Manager\n - 6.14.x: ClearPass 6.14.0 and above\n - 6.12.x: ClearPass 6.12.8-HF and above\n - 6.11.x: ClearPass 6.11.15 and above\n\nNOTE: Customers running HPE Networking ClearPass Policy Manager 6.12.x are encouraged to upgrade to a supported software branch for complete remediation.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at\nhttps://networkingsupport.hpe.com/home.",
          "product_ids": [
            "CPPM-6.11.15",
            "CPPM-6.14.0"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services Aruba Networking for any configuration assistance if needed.",
          "product_ids": [
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "title": "Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Daniel Jensen (@dozernz)"
          ],
          "summary": "This vulnerability was discovered and reported by Daniel Jensen (@dozernz)."
        }
      ],
      "cve": "CVE-2026-73769",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-44",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "CPPM-6.14.0",
          "CPPM-6.12.8-HF",
          "CPPM-6.11.15"
        ],
        "known_affected": [
          ">=6.12.0|<=6.12.8",
          ">=6.11.0|<=6.11.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Networking ClearPass Policy Manager to one of the following versions:\n\nHPE Networking ClearPass Policy Manager\n - 6.14.x: ClearPass 6.14.0 and above\n - 6.12.x: ClearPass 6.12.8-HF and above\n - 6.11.x: ClearPass 6.11.15 and above\n\nNOTE: Customers running HPE Networking ClearPass Policy Manager 6.12.x are encouraged to upgrade to a supported software branch for complete remediation.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at\nhttps://networkingsupport.hpe.com/home.",
          "product_ids": [
            "CPPM-6.11.15",
            "CPPM-6.12.8-HF",
            "CPPM-6.14.0"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services Aruba Networking for any configuration assistance if needed.",
          "product_ids": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "title": "Authenticated Remote Code Execution in CPPM Web Interface"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "n3k"
          ],
          "summary": "This vulnerability was discovered and reported by n3k."
        }
      ],
      "cve": "CVE-2026-73788",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-51",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "CPPM-6.14.0",
          "CPPM-6.12.8-HF",
          "CPPM-6.11.15"
        ],
        "known_affected": [
          ">=6.12.0|<=6.12.8",
          ">=6.11.0|<=6.11.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Networking ClearPass Policy Manager to one of the following versions:\n\nHPE Networking ClearPass Policy Manager\n - 6.14.x: ClearPass 6.14.0 and above\n - 6.12.x: ClearPass 6.12.8-HF and above\n - 6.11.x: ClearPass 6.11.15 and above\n\nNOTE: Customers running HPE Networking ClearPass Policy Manager 6.12.x are encouraged to upgrade to a supported software branch for complete remediation.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at\nhttps://networkingsupport.hpe.com/home.",
          "product_ids": [
            "CPPM-6.11.15",
            "CPPM-6.12.8-HF",
            "CPPM-6.14.0"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services Aruba Networking for any configuration assistance if needed.",
          "product_ids": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "title": "Privilege Escalation in ClearPass OnGuard Agent"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "0x50d"
          ],
          "summary": "This vulnerability was discovered and reported by 0x50d."
        }
      ],
      "cve": "CVE-2026-73789",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading to unauthorized prolonged use of network resources.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-54",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "CPPM-6.14.0",
          "CPPM-6.12.8-HF",
          "CPPM-6.11.15"
        ],
        "known_affected": [
          ">=6.12.0|<=6.12.8",
          ">=6.11.0|<=6.11.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To address the vulnerabilities described above in the affected software branches, it is recommended to upgrade HPE Networking ClearPass Policy Manager to one of the following versions:\n\nHPE Networking ClearPass Policy Manager\n - 6.14.x: ClearPass 6.14.0 and above\n - 6.12.x: ClearPass 6.12.8-HF and above\n - 6.11.x: ClearPass 6.11.15 and above\n\nNOTE: Customers running HPE Networking ClearPass Policy Manager 6.12.x are encouraged to upgrade to a supported software branch for complete remediation.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at\nhttps://networkingsupport.hpe.com/home.",
          "product_ids": [
            "CPPM-6.11.15",
            "CPPM-6.12.8-HF",
            "CPPM-6.14.0"
          ],
          "url": "https://networkingsupport.hpe.com/downloads;fileTypes=SOFTWARE"
        },
        {
          "category": "workaround",
          "date": "2026-09-09T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above, along with accounting controls for tracking and logging user activities and resource usage. You may contact HPE Services Aruba Networking for any configuration assistance if needed.",
          "product_ids": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            ">=6.12.0|<=6.12.8",
            ">=6.11.0|<=6.11.14"
          ]
        }
      ],
      "title": "Unauthenticated Insecure Parameter Manipulation allows Data Tampering In CPPM Web Interface"
    }
  ]
}