Lucene search

K
cveCiscoCVE-2013-5530
HistoryOct 25, 2013 - 3:52 a.m.

CVE-2013-5530

2013-10-2503:52:54
CWE-78
cisco
web.nvd.nist.gov
29
cisco
ise
web framework
remote execution
tcp port 443
cve-2013-5530
vulnerability

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

74.5%

The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443, aka Bug ID CSCuh81511.

Affected configurations

Nvd
Node
ciscoidentity_services_engine_softwareMatch1.0
OR
ciscoidentity_services_engine_softwareMatch1.1
OR
ciscoidentity_services_engine_softwareMatch1.1.1
OR
ciscoidentity_services_engine_softwareMatch1.1.2
OR
ciscoidentity_services_engine_softwareMatch1.1.3
OR
ciscoidentity_services_engine_softwareMatch1.1.4
OR
ciscoidentity_services_engine_softwareMatch1.2
VendorProductVersionCPE
ciscoidentity_services_engine_software1.0cpe:2.3:a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.2cpe:2.3:a:cisco:identity_services_engine_software:1.1.2:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.3cpe:2.3:a:cisco:identity_services_engine_software:1.1.3:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.4cpe:2.3:a:cisco:identity_services_engine_software:1.1.4:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.2cpe:2.3:a:cisco:identity_services_engine_software:1.2:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

74.5%