{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "summary",
        "text": "HPE Networking has released patches for the HPE Networking ClearPass Policy Manager (CPPM) that address multiple security vulnerabilities.",
        "title": "Summary"
      },
      {
        "category": "general",
        "text": "These vulnerabilities affect the following HPE Networking ClearPass Policy Manager (CPPM) software versions unless specifically noted otherwise in the details section:\n\nHPE Networking ClearPass Policy Manager (CPPM)\n  - CPPM 6.14.0 and below\n  - CPPM 6.11.15 and below",
        "title": "Affected Products"
      },
      {
        "category": "general",
        "text": "Any other HPE Networking products and software versions not specifically listed above are not affected by these vulnerabilities.",
        "title": "Unaffected Products"
      },
      {
        "category": "other",
        "text": "These vulnerabilities were generally discovered by internal security research at HPE Networking. HPE Networking is not aware of any public discussion or exploit code that targets the listed vulnerabilities as of the release date of this advisory. Customers are strongly urged to patch their instances due to the complexity, breadth, and impact of these vulnerabilities.",
        "title": "Exploitation and Public Discussion"
      },
      {
        "category": "general",
        "text": "Complete information on reporting security vulnerabilities in HPE Networking products and obtaining assistance with security incidents is available at:\nhttps://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us\n \nFor reporting *NEW* HPE Networking security issues, email can be sent to networking-psirt(at)hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at:\nhttps://www.hpe.com/info/psrt-pgp-key",
        "title": "HPE Networking SIRT Security Procedures"
      },
      {
        "category": "legal_disclaimer",
        "text": "(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information.",
        "title": "Legal Disclaimer"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "Email: networking-psirt(at)hpe.com - For further details please see http://www.hpe.com/support/security-response-policy",
      "issuing_authority": "HPE Networking's Security Incident Response Team (SIRT) is responsible for receiving, tracking, managing, and disclosing vulnerabilities in HPE Aruba Networking products. The HPE Aruba Networking SIRT actively works with industry, non-profit, government organizations, and the security community when vulnerabilities are reported. A security vulnerability is defined as any weakness in a product that allows an attacker to compromise the confidentiality, integrity, or availability of a product, customer infrastructure, or IT system through an HPE Aruba Networking product in that environment.",
      "name": "HPE Networking",
      "namespace": "https://www.hpe.com/support/security-response-policy"
    },
    "references": [
      {
        "summary": "Original Advisory",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05158en_us&docLocale=en_US"
      },
      {
        "summary": "HPE Networking Security Advisory Archive",
        "url": "https://csaf.arubanetworking.hpe.com/"
      },
      {
        "summary": "HPE Networking Product Security Incident Response Policy",
        "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00100637en_us"
      }
    ],
    "title": "Multiple Vulnerabilities in HPE Networking ClearPass Policy Manager (CPPM)",
    "tracking": {
      "current_release_date": "2026-10-06T16:00:00.000Z",
      "generator": {
        "date": "2026-10-06T16:00:00.000Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.5.37"
        }
      },
      "id": "HPESBNW05158",
      "initial_release_date": "2026-10-06T16:00:00.000Z",
      "revision_history": [
        {
          "date": "2026-10-06T16:00:00.000Z",
          "number": "1",
          "summary": "Initial Publication"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "CPPM 6.14.1",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager (CPPM)",
                  "product_id": "6.14.1"
                }
              },
              {
                "category": "product_version",
                "name": "CPPM 6.11.16",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager (CPPM)",
                  "product_id": "6.11.16"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=6.14.0|<=6.14.0",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager (CPPM)",
                  "product_id": ">=6.14.0|<=6.14.0"
                }
              },
              {
                "category": "product_version_range",
                "name": "vers:semver/>=6.11.0|<=6.11.15",
                "product": {
                  "name": "HPE Networking ClearPass Policy Manager (CPPM)",
                  "product_id": ">=6.11.0|<=6.11.15"
                }
              }
            ],
            "category": "product_name",
            "name": "ClearPass Policy Manager (CPPM)"
          }
        ],
        "category": "vendor",
        "name": "HPE Networking"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79798",
      "notes": [
        {
          "category": "details",
          "text": "SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-430",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.9,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "temporalScore": 9.9,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated SQL Injection Vulnerabilities in ClearPass Policy Manager Web-Based Management Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-76750",
      "notes": [
        {
          "category": "details",
          "text": "Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-400, VULN-513",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated Deserialization of Untrusted Data allows Remote Code Execution in the Web Interface of HPE Networking ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-76751",
      "notes": [
        {
          "category": "details",
          "text": "A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-403, VULN-405, VULN-406",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Missing Integrity Verification in the OnGuard Agent of ClearPass Policy Manager Allows Unauthenticated Remote Code Execution"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-76752",
      "notes": [
        {
          "category": "details",
          "text": "Authentication bypass vulnerabilities exist in the web-based management and API interfaces of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to circumvent existing authentication controls and gain administrative access to the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-422, VULN-442",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authentication Bypass Vulnerabilities in HPE Networking ClearPass Policy Manager Allow Unauthorized Administrative Access"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-76753",
      "notes": [
        {
          "category": "details",
          "text": "A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-426",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated Format String Vulnerability in HPE Networking ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-76754",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in an affected interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-436",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated SQL Injection Vulnerability leads to Remote Code Execution in ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79796",
      "notes": [
        {
          "category": "details",
          "text": "Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain unauthorized access to the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-396, VULN-438",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authentication Bypass Vulnerabilities in ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79801",
      "notes": [
        {
          "category": "details",
          "text": "A missing integrity verification vulnerability in the client agent software of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to introduce untrusted code. Successful exploitation could allow an attacker to execute arbitrary code on the affected client system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-473",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated Missing Integrity Verification allows Remote Code Execution in ClearPass Policy Manager Client Agent"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79805",
      "notes": [
        {
          "category": "details",
          "text": "An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-397",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.8,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 9.8,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Path Traversal Vulnerability Leads to Unauthorized File Access and Modification in ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79794",
      "notes": [
        {
          "category": "details",
          "text": "A SQL injection vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-428",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 9.1,
            "environmentalSeverity": "CRITICAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "temporalScore": 9.1,
            "temporalSeverity": "CRITICAL",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79797",
      "notes": [
        {
          "category": "details",
          "text": "An improper access control vulnerability exists in the Android client application for HPE Networking ClearPass Policy Manager, where application functionality may be invoked by untrusted sources. Successful exploitation could allow an unauthenticated remote attacker, with user interaction, to obtain sensitive information from the affected user.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-476",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Improper Access Control in HPE Networking ClearPass Android Client Application"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79799",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-433",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated Stored Cross-Site Scripting (XSS) Vulnerability in ClearPass Policy Manager Web-Based Management Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79800",
      "notes": [
        {
          "category": "details",
          "text": "An authenticated path traversal vulnerability exists in the command line interface of ClearPass Policy Manager. Successful exploitation could allow a low-privileged authenticated remote attacker to execute arbitrary code with elevated privileges on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-468",
          "title": "Internal References"
        },
        {
          "category": "other",
          "text": "Fixed in 6.14.1 only. It is not applicable to 6.11.16.",
          "title": "Note"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n\nNOTE: This vulnerability is fixed in CPPM 6.14.1 only. It is not applicable to the 6.11.x branch.\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com",
          "product_ids": [
            "6.14.1"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0"
          ]
        }
      ],
      "title": "Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79802",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability exists in the client software of ClearPass Policy Manager. Successful exploitation could allow an attacker who is able to supply crafted input to the affected software to execute arbitrary commands with elevated privileges on the affected host.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-478",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Command Injection Vulnerability in the ClearPass Policy Manager Client Software"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79803",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability exists in the API of ClearPass Policy Manager. Successful exploitation could allow an authenticated remote attacker to escalate privileges and gain administrative control of the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-521",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 8.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 8.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Command Injection Leading to Privilege Escalation in ClearPass Policy Manager API"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79806",
      "notes": [
        {
          "category": "details",
          "text": "A privilege escalation vulnerability in the ClearPass Policy Manager OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit allows a malicious user to escalate to root privileges on the affected Linux client.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1415",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Local Privilege Escalation in ClearPass Policy Manager OnGuard Linux Agent"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79807",
      "notes": [
        {
          "category": "details",
          "text": "A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-474",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Local Missing Integrity Verification Vulnerability leads to Local Privilege Escalation in the ClearPass Policy Manager Windows Client Software"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79808",
      "notes": [
        {
          "category": "details",
          "text": "A buffer overflow vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an authenticated local user to execute arbitrary code with elevated privileges on the affected host or to disrupt the availability of the affected service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-492",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.8,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 7.8,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Local Authenticated Buffer Overflow Vulnerability in the ClearPass Policy Manager OnGuard Agent"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79809",
      "notes": [
        {
          "category": "details",
          "text": "An unauthenticated path traversal vulnerability exists in an API endpoint of ClearPass Policy Manager. Successful exploitation of this vulnerability allows an unauthenticated remote attacker to influence authorization decisions and be assigned an unintended role.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-446",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated Path Traversal in ClearPass Policy Manager API Endpoint Leads to Authorization Bypass"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79810",
      "notes": [
        {
          "category": "details",
          "text": "Remote code execution vulnerabilities exist in the affected interface of HPE Networking ClearPass Policy Manager that could allow an authenticated remote attacker with high privileges to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-520, VULN-1414",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Remote Code Execution Vulnerabilities in HPE Networking ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Haxship1337"
          ],
          "organization": "Bugcrowd",
          "summary": "This vulnerability was discovered by Haxship1337 and reported through HPE Networking's bug bounty program."
        }
      ],
      "cve": "CVE-2026-79811",
      "notes": [
        {
          "category": "details",
          "text": "A SQL injection vulnerability in the API of ClearPass Policy Manager could allow a remote authenticated attacker with administrative privileges to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to execute arbitrary database commands.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-587",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.2,
            "environmentalSeverity": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "temporalScore": 7.2,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated SQL Injection allows Remote Code Execution in ClearPass Policy Manager API"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79814",
      "notes": [
        {
          "category": "details",
          "text": "An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow malicious users on a local instance to elevate their user privileges if certain preconditions outside of the attacker's control are met. Successful exploitation could allow a local attacker to execute arbitrary code with elevated privileges on the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-486",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.7,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.7,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Local Arbitrary File Write Leading to Local Privilege Escalation in ClearPass Policy Manager OnGuard Agent"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79813",
      "notes": [
        {
          "category": "details",
          "text": "A local privilege escalation vulnerability exists in the ClearPass client software. Successful exploitation could allow a low-privileged local user to execute commands with elevated privileges on the affected system, if certain conditions outside of the attacker's control are met.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-472",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.7,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.7,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Local Privilege Escalation in ClearPass Client Software"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79815",
      "notes": [
        {
          "category": "details",
          "text": "A command injection vulnerability in the OnGuard agent of ClearPass Policy Manager could allow an authenticated remote attacker to inject arbitrary commands. Successful exploitation could allow an attacker to execute commands with elevated privileges on the affected Windows endpoint.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1416",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 6.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Command Injection Vulnerability in the ClearPass Policy Manager OnGuard Agent"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79812",
      "notes": [
        {
          "category": "details",
          "text": "A denial of service vulnerability exists in the OnGuard agent of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an authenticated local attacker to interrupt the normal operation of the agent service.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-491",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.1,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 6.1,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authenticated Local Denial-of-Service Vulnerability in the OnGuard Agent of ClearPass Policy Manager"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79817",
      "notes": [
        {
          "category": "details",
          "text": "A sensitive information disclosure vulnerability exists in the client software of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an attacker with local access to the affected system to obtain sensitive information.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-477",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 5.5,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "temporalScore": 5.5,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Local Disclosure of Sensitive Information in HPE Networking ClearPass Policy Manager Client Software"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79816",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in a client interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against a user of the affected client interface. Successful exploitation could allow an attacker to execute arbitrary script code in a victim's browser context within the affected client interface.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-1417",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.4,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Unauthenticated DOM-Based Cross-Site Scripting (XSS) Vulnerability in the ClearPass Policy Manager Client Interface"
    },
    {
      "acknowledgments": [
        {
          "organization": "HPE Networking"
        }
      ],
      "cve": "CVE-2026-79818",
      "notes": [
        {
          "category": "details",
          "text": "A vulnerability in an API interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to obtain sensitive information from the affected system.",
          "title": "Details"
        },
        {
          "category": "other",
          "text": "VULN-443",
          "title": "Internal References"
        }
      ],
      "product_status": {
        "fixed": [
          "6.14.1",
          "6.11.16"
        ],
        "known_affected": [
          ">=6.14.0|<=6.14.0",
          ">=6.11.0|<=6.11.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To address the vulnerabilities described in the Details Section, HPE Networking recommends upgrading the HPE Networking ClearPass Policy Manager (CPPM) products to the following software versions (as applicable):\n\n  - CPPM 6.14.1 and above\n  - CPPM 6.11.16 and above\n\nSoftware versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal at: https://networkingsupport.hpe.com\n\nNOTE: Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise and are not covered by this security advisory. For deployments running software versions that are past End of Support (EoS), HPE Networking has not assessed exposure to the vulnerabilities referenced in this advisory. As a result, such installations should be considered potentially impacted by the listed CVE. Customers are strongly encouraged to upgrade to a supported software release to ensure proper evaluation and remediation.",
          "product_ids": [
            "6.14.1",
            "6.11.16"
          ],
          "url": "https://networkingsupport.hpe.com"
        },
        {
          "category": "workaround",
          "date": "2026-10-06T16:00:00.000Z",
          "details": "To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage.",
          "product_ids": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 5.3,
            "environmentalSeverity": "MEDIUM",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "temporalScore": 5.3,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            ">=6.14.0|<=6.14.0",
            ">=6.11.0|<=6.11.15"
          ]
        }
      ],
      "title": "Authentication Bypass in the API Interface Allows Unauthorized Information Disclosure in ClearPass Policy Manager"
    }
  ]
}