Security

 View Only
Expand all | Collapse all

Does version 6.11.13 includes a fix for CVE-2025-37122

This thread has been viewed 15 times
  • 1.  Does version 6.11.13 includes a fix for CVE-2025-37122

    Posted Dec 30, 2025 01:09 PM
    Edited by zouhsaine Dec 30, 2025 01:12 PM

    Hello,

    I hope everyone is having a great day.

    I couldn't find this info, but does version 6.11.13 includes a fix for CVE-2025-37122 

    https://networkingsupport.hpe.com/notifications/Tm90aWZpY2F0aW9uOjExNjIzMw%3D%3D;notificationCategory=Security

    Also i couldn't find anything here in resolved issues:

    https://arubanetworking.hpe.com/techdocs/ClearPass/CP_ReleaseNotes_6.x.x/Default.htm#ReleaseNotes/Resolved/Resolved-6.11.13.htm?TocPath=About%2520ClearPass%25206.11.x%257CResolved%2520Issues%2520in%2520ClearPass%25206.11.x%257C_____1

    -------------------------------------------



  • 2.  RE: Does version 6.11.13 includes a fix for CVE-2025-37122
    Best Answer

    Posted Dec 31, 2025 08:37 AM

    The HPE security bulletin confirms this.

    HPESBNW04950 states that CVE-2025-37122 is fixed in the ClearPass 6.11.12 hotfix. Since 6.11.13 is a cumulative patch release, it includes all fixes from 6.11.12 and earlier.

    Reference: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04950en_us&docLocale=en_US

    So yes, 6.11.13 includes the fix for CVE-2025-37122.

    -------------------------------------------