Lucene search

K
cveCiscoCVE-2015-6317
HistoryJan 23, 2016 - 5:59 a.m.

CVE-2015-6317

2016-01-2305:59:00
CWE-284
cisco
web.nvd.nist.gov
29
cisco
ise
cve-2015-6317
bug id cscuu45926
nvd
identity services engine
web resource access restrictions

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

34.1%

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

Affected configurations

Nvd
Node
ciscoidentity_services_engine_softwareMatch1.0.4.573
OR
ciscoidentity_services_engine_softwareMatch1.0_base
OR
ciscoidentity_services_engine_softwareMatch1.0_mr_base
OR
ciscoidentity_services_engine_softwareMatch1.1.1p1
OR
ciscoidentity_services_engine_softwareMatch1.1.1p2
OR
ciscoidentity_services_engine_softwareMatch1.1.1p3
OR
ciscoidentity_services_engine_softwareMatch1.1.1p4
OR
ciscoidentity_services_engine_softwareMatch1.1.1p5
OR
ciscoidentity_services_engine_softwareMatch1.1.1p6
OR
ciscoidentity_services_engine_softwareMatch1.1.2p1
OR
ciscoidentity_services_engine_softwareMatch1.1.2p2
OR
ciscoidentity_services_engine_softwareMatch1.1.2p3
OR
ciscoidentity_services_engine_softwareMatch1.1.2p4
OR
ciscoidentity_services_engine_softwareMatch1.1.2p5
OR
ciscoidentity_services_engine_softwareMatch1.1.2p6
OR
ciscoidentity_services_engine_softwareMatch1.1.2p7
OR
ciscoidentity_services_engine_softwareMatch1.1.2p8
OR
ciscoidentity_services_engine_softwareMatch1.1.2p9
OR
ciscoidentity_services_engine_softwareMatch1.1.3p1
OR
ciscoidentity_services_engine_softwareMatch1.1.3p2
OR
ciscoidentity_services_engine_softwareMatch1.1.3p3
OR
ciscoidentity_services_engine_softwareMatch1.1.3p4
OR
ciscoidentity_services_engine_softwareMatch1.1.3p5
OR
ciscoidentity_services_engine_softwareMatch1.1.3p6
OR
ciscoidentity_services_engine_softwareMatch1.1.3p7
OR
ciscoidentity_services_engine_softwareMatch1.1.4p1
OR
ciscoidentity_services_engine_softwareMatch1.1.4p2
OR
ciscoidentity_services_engine_softwareMatch1.1.4p3
OR
ciscoidentity_services_engine_softwareMatch1.1.4p4
OR
ciscoidentity_services_engine_softwareMatch1.1.4p5
OR
ciscoidentity_services_engine_softwareMatch1.1.4p6
OR
ciscoidentity_services_engine_softwareMatch1.1.4p7
OR
ciscoidentity_services_engine_softwareMatch1.1_base
OR
ciscoidentity_services_engine_softwareMatch1.2\(0.747\)
OR
ciscoidentity_services_engine_softwareMatch1.2\(0.793\)
OR
ciscoidentity_services_engine_softwareMatch1.2\(1.198\)
OR
ciscoidentity_services_engine_softwareMatch1.2\(1.901\)
OR
ciscoidentity_services_engine_softwareMatch1.2.0.899p14
OR
ciscoidentity_services_engine_softwareMatch1.2.1p1
OR
ciscoidentity_services_engine_softwareMatch1.2.1p2
OR
ciscoidentity_services_engine_softwareMatch1.2_base
OR
ciscoidentity_services_engine_softwareMatch1.3\(0.722\)
OR
ciscoidentity_services_engine_softwareMatch1.3\(0.876\)
OR
ciscoidentity_services_engine_softwareMatch1.3\(106.146\)
OR
ciscoidentity_services_engine_softwareMatch1.3\(120.135\)
OR
ciscoidentity_services_engine_softwareMatch1.4\(0.109\)
OR
ciscoidentity_services_engine_softwareMatch1.4\(0.181\)
OR
ciscoidentity_services_engine_softwareMatch1.4\(0.253\)
VendorProductVersionCPE
ciscoidentity_services_engine_software1.0.4.573cpe:2.3:a:cisco:identity_services_engine_software:1.0.4.573:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0_basecpe:2.3:a:cisco:identity_services_engine_software:1.0_base:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0_mr_basecpe:2.3:a:cisco:identity_services_engine_software:1.0_mr_base:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p1:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p2:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p3:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p4:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p5:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.1cpe:2.3:a:cisco:identity_services_engine_software:1.1.1:p6:*:*:*:*:*:*
ciscoidentity_services_engine_software1.1.2cpe:2.3:a:cisco:identity_services_engine_software:1.1.2:p1:*:*:*:*:*:*
Rows per page:
1-10 of 481

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:C/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

34.1%

Related for CVE-2015-6317