CVE 6.1 MEDIUM

Unauthenticated Reflected Cross-Site Scripting_CVE-2025-37122

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browser in the context of the affected interface.

Basic Information

ID CVE-2025-37122
Source hpe
Published Sep 17, 2025 at 19:31
Modified Sep 17, 2025 at 19:42

Affected Product

Vendor Hewlett Packard Enterprise (HPE)
Product HPE Aruba Networking ClearPass Policy Manager
Version 6.12.0
Affected Versions Hewlett Packard Enterprise (HPE) HPE Aruba Networking ClearPass Policy Manager 6.12.0
Hewlett Packard Enterprise (HPE) HPE Aruba Networking ClearPass Policy Manager 6.11.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.