First published: Sun Sep 16 2012(Updated: )
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =1.0 | |
Cisco Identity Services Engine | =1.0.4 | |
Cisco Identity Services Engine | =1.0mr | |
Cisco Identity Services Engine | =1.1 | |
Cisco Identity Services Engine | =1.1.1 | |
Cisco Identity Services Engine (ISE) | =3300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3908 is classified as a medium severity vulnerability due to its potential for Cross-Site Request Forgery attacks.
To mitigate CVE-2012-3908, apply the latest cumulative patch from Cisco for the Identity Services Engine software.
CVE-2012-3908 affects users of Cisco Identity Services Engine software versions before 1.1.0.665 Cumulative Patch 1.
CVE-2012-3908 can allow remote attackers to hijack the authentication of administrators through CSRF attacks.
Yes, CVE-2012-3908 is exploitable remotely, allowing attackers to manipulate user sessions without physical access.