First published: Fri Oct 25 2013(Updated: )
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =1.0 | |
Cisco Identity Services Engine | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5531 is considered a critical vulnerability that allows remote attackers to bypass authentication.
To mitigate CVE-2013-5531, users should upgrade Cisco Identity Services Engine software to version 1.1.1 or later.
Exploitation of CVE-2013-5531 can lead to unauthorized access to support-bundle configuration and credentials data.
CVE-2013-5531 affects Cisco Identity Services Engine versions 1.0 and 1.1 prior to version 1.1.1.
Yes, CVE-2013-5531 can be exploited remotely through a crafted session on TCP port 443.