CVE-2013-5531: Medium severity cisco identity services engine vulnerability
Published Oct 25, 2013
·Updated
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
Affected Software
2 affected components
Cisco Identity Services Engine Software=1.0
Cisco Identity Services Engine Software=1.1
Event History
Oct 25, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5531?
CVE-2013-5531 is considered a critical vulnerability that allows remote attackers to bypass authentication.
2
How do I fix CVE-2013-5531?
To mitigate CVE-2013-5531, users should upgrade Cisco Identity Services Engine software to version 1.1.1 or later.
3
What types of data can be accessed due to CVE-2013-5531?
Exploitation of CVE-2013-5531 can lead to unauthorized access to support-bundle configuration and credentials data.
4
Which versions of Cisco Identity Services Engine are affected by CVE-2013-5531?
CVE-2013-5531 affects Cisco Identity Services Engine versions 1.0 and 1.1 prior to version 1.1.1.
5
Can CVE-2013-5531 be exploited remotely?
Yes, CVE-2013-5531 can be exploited remotely through a crafted session on TCP port 443.