Lucene search

K
nvd[email protected]NVD:CVE-2015-0757
HistoryMay 29, 2015 - 3:59 p.m.

CVE-2015-0757

2015-05-2915:59:11
CWE-200
web.nvd.nist.gov
6

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

53.0%

The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.

Affected configurations

Nvd
Node
ciscoidentity_services_engine_softwareMatch1.2\(1.901\)
OR
ciscoidentity_services_engine_softwareMatch1.3\(0.722\)
VendorProductVersionCPE
ciscoidentity_services_engine_software1.2(1.901)cpe:2.3:a:cisco:identity_services_engine_software:1.2\(1.901\):*:*:*:*:*:*:*
ciscoidentity_services_engine_software1.3(0.722)cpe:2.3:a:cisco:identity_services_engine_software:1.3\(0.722\):*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.002

Percentile

53.0%

Related for NVD:CVE-2015-0757