Lucene search

K
ciscoCiscoCISCO-SA-20150611-CVE-2015-4182
HistoryJun 11, 2015 - 3:51 p.m.

Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability

2015-06-1115:51:38
tools.cisco.com
18

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

EPSS

0.001

Percentile

49.2%

A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or modify certain device settings.

The vulnerability is due to improper controls on certain pages in the web interface. An attacker with authenticated access to the administrative web interface could access pages that should be restricted to a more privileged access roll.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoidentity_services_engine_softwareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
VendorProductVersionCPE
ciscoidentity_services_engine_softwareanycpe:2.3:a:cisco:identity_services_engine_software:any:*:*:*:*:*:*:*

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

EPSS

0.001

Percentile

49.2%

Related for CISCO-SA-20150611-CVE-2015-4182