Lucene search

K
cveCiscoCVE-2013-3471
HistoryAug 29, 2013 - 12:07 p.m.

CVE-2013-3471

2013-08-2912:07:54
CWE-255
cisco
web.nvd.nist.gov
29
captive portal
cisco ise
remote attackers
username discovery
password discovery
bug id cscug02515
cve-2013-3471

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

53.0%

The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.

Affected configurations

Nvd
Node
ciscoidentity_services_engine_softwareMatch-
VendorProductVersionCPE
ciscoidentity_services_engine_software-cpe:2.3:a:cisco:identity_services_engine_software:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

53.0%

Related for CVE-2013-3471