Lucene search

K
ciscoCiscoCISCO-SA-20131023-CVE-2013-5531
HistoryOct 23, 2013 - 4:35 p.m.

Cisco ISE Support Information Download Authentication Bypass Vulnerability

2013-10-2316:35:05
tools.cisco.com
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

58.9%

A vulnerability in the implementation of the authentication code that is used to validate requests to download a product support bundle could allow an unauthenticated, remote attacker to download a full product support bundle.

The vulnerability is due to an error in the logic that is used to validate support bundle access requests. An attacker could exploit this vulnerability by sending a crafted request to the vulnerable system. An exploit could allow an attacker to obtain a full copy of the product configuration or other sensitive information including administrative credentials.

Cisco confirmed the vulnerability in a security advisory and released software updates.

A successful exploit could allow an attacker to gain access to information in support packages stored on the targeted system. The file contents may include authentication credentials that could allow the attacker to conduct further exploits against the targeted system or other related systems.

Affected configurations

Vulners
Node
ciscoidentity_services_engine_softwareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
VendorProductVersionCPE
ciscoidentity_services_engine_softwareanycpe:2.3:a:cisco:identity_services_engine_software:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.002

Percentile

58.9%

Related for CISCO-SA-20131023-CVE-2013-5531