Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*
- <= 3.1
- <= 3.2 Patch 7
- <= 3.3 Patch 7
- <= 3.4 Patch 1
An information disclosure vulnerability has been identified in the web-based management interface of Cisco Identity Services Engine (ISE). This vulnerability allows an authenticated, remote attacker with read-only Administrator privileges to access sensitive information from the affected device. The issue arises because certain files do not have adequate data protection, enabling the attacker to view passwords and other information that should be restricted to high-privileged users.
Exploitation of this vulnerability could result in unauthorized access to sensitive information, such as passwords, that are not normally visible to read-only administrators.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Identity Service Engine support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.