Lucene search

K
ciscoCiscoCISCO-SA-20150106-CVE-2014-8017
HistoryJan 06, 2015 - 9:14 p.m.

Cisco Identity Services Engine Periodic Backup Password Disclosure Vulnerability

2015-01-0621:14:07
tools.cisco.com
21

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.4%

A vulnerability in the periodic backup functionality of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to discover the password used to encrypt the backup on the system.

The vulnerability is due to improper processing of certain client requests by the affected software. An attacker could exploit this vulnerability by submitting a crafted request that is designed to trigger the issue in the affected software. If the request is processed, Cisco ISE could generate a reply that contains the backup password. An attacker could use this password to decrypt the backup on the system and disclose sensitive information.

Cisco has confirmed the vulnerability in a security notice and released updated software.

To exploit the vulnerability, the attacker may need access to trusted or internal networks to transmit a crafted request to the targeted system. This access requirement could limit the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscoidentity_services_engine_softwareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
VendorProductVersionCPE
ciscoidentity_services_engine_softwareanycpe:2.3:a:cisco:identity_services_engine_software:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

68.4%

Related for CISCO-SA-20150106-CVE-2014-8017