CVE-2012-3908: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3908?
CVE-2012-3908 is classified as a medium severity vulnerability due to its potential for Cross-Site Request Forgery attacks.
How do I fix CVE-2012-3908?
To mitigate CVE-2012-3908, apply the latest cumulative patch from Cisco for the Identity Services Engine software.
Who is affected by CVE-2012-3908?
CVE-2012-3908 affects users of Cisco Identity Services Engine software versions before 1.1.0.665 Cumulative Patch 1.
What types of attacks can CVE-2012-3908 enable?
CVE-2012-3908 can allow remote attackers to hijack the authentication of administrators through CSRF attacks.
Is CVE-2012-3908 exploitable remotely?
Yes, CVE-2012-3908 is exploitable remotely, allowing attackers to manipulate user sessions without physical access.