Lucene search

K
cveCiscoCVE-2011-3290
HistorySep 21, 2011 - 4:55 p.m.

CVE-2011-3290

2011-09-2116:55:04
CWE-255
cisco
web.nvd.nist.gov
28
cisco
ise
oracle
cve-2011-3290
nvd
bug id cscts59135

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.011

Percentile

84.2%

Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.

Affected configurations

Nvd
Node
ciscoidentity_services_engine
AND
ciscoidentity_services_engine_softwareRange1.0.4
OR
ciscoidentity_services_engine_softwareMatch1.0
OR
ciscoidentity_services_engine_softwareMatch1.0mr
VendorProductVersionCPE
ciscoidentity_services_engine*cpe:2.3:h:cisco:identity_services_engine:*:*:*:*:*:*:*:*
ciscoidentity_services_engine_software*cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0cpe:2.3:a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0mrcpe:2.3:a:cisco:identity_services_engine_software:1.0mr:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.8

Confidence

Low

EPSS

0.011

Percentile

84.2%

Related for CVE-2011-3290