CVE-2022-37877

HIGH

Aruba ClearPass Policy Mgr <6.10.6, <6.9.11 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): 6.10.x: 6.10.6 and below; 6.9.x: 6.9.11 and below. Aruba has released upgrades for Aruba ClearPass Policy Manager that address this security vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (1)
arubanetworks/clearpass_policy_manager 6.9.0 - 6.9.12
Published Sep 20, 2022
Tracked Since Feb 18, 2026