First published: Fri Oct 25 2013(Updated: )
Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service (exhaustion of the account supply) via a series of requests within one session, aka Bug ID CSCue94287.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5521 has a moderate severity rating as it allows for denial of service through account exhaustion.
To fix CVE-2013-5521, ensure that you have updated your Cisco Identity Services Engine software to the latest version provided by Cisco.
CVE-2013-5521 affects Cisco Identity Services Engine Software in its various versions.
CVE-2013-5521 facilitates a denial of service attack that exhausts the available guest account supply.
Yes, CVE-2013-5521 can be exploited remotely by sending a series of requests within a single session.