Lucene search

K
ciscoCiscoCISCO-SA-20150827-CVE-2015-6266
HistoryAug 27, 2015 - 11:46 p.m.

Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability

2015-08-2723:46:05
tools.cisco.com
35

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.1%

A vulnerability in the Cisco Identity Services Engine (ISE) guest portal could allow an unauthenticated, remote attacker to view a customized page on the guest portal.

The vulnerability is due to lack of access control for the uploaded HTML files. An attacker could exploit this vulnerability by crafting an HTTP request that points to the filename of the customized page.

Cisco has confirmed the vulnerability; however, software updates are not available.

To exploit this vulnerability, the attacker must send a crafted HTTP request to the filename of the customized page on the guest portal. The Cisco ISE guest portal is configured to use customized uploaded HTML files, making an exploit easier to accomplish. Environments that restrict access from untrusted sources could make successful exploitation more difficult.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoidentity_services_engine_softwareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
VendorProductVersionCPE
ciscoidentity_services_engine_softwareanycpe:2.3:a:cisco:identity_services_engine_software:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.003

Percentile

66.1%

Related for CISCO-SA-20150827-CVE-2015-6266