Executive brief
HPE CPPM (Aruba ClearPass Policy Manager) is a network access control platform used to manage user identity and device compliance. A vulnerability in its web interface allows authenticated attackers to execute arbitrary commands on the underlying operating system, potentially leading to complete system compromise and unauthorized access to corporate network resources.
Technical details
This vulnerability in the CPPM web interface allows an authenticated remote attacker to access directory information and execute arbitrary commands on the underlying operating system. The attack requires valid authentication credentials and network access to the web interface. Successful exploitation grants an attacker command execution capability on the host system, which can lead to lateral movement, data theft, or further network compromise. The CVSS score of 7.2 reflects the high impact of arbitrary command execution, moderated by the requirement for prior authentication.
Affected products
- HPE CPPM
Timeline
- 2026-09-09: disclosed