Lucene search

K
nvd[email protected]NVD:CVE-2011-3290
HistorySep 21, 2011 - 4:55 p.m.

CVE-2011-3290

2011-09-2116:55:04
CWE-255
web.nvd.nist.gov
7

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.2%

Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.

Affected configurations

Nvd
Node
ciscoidentity_services_engine
AND
ciscoidentity_services_engine_softwareRange1.0.4
OR
ciscoidentity_services_engine_softwareMatch1.0
OR
ciscoidentity_services_engine_softwareMatch1.0mr
VendorProductVersionCPE
ciscoidentity_services_engine*cpe:2.3:h:cisco:identity_services_engine:*:*:*:*:*:*:*:*
ciscoidentity_services_engine_software*cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0cpe:2.3:a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.0mrcpe:2.3:a:cisco:identity_services_engine_software:1.0mr:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.011

Percentile

84.2%

Related for NVD:CVE-2011-3290