First published: Mon Dec 22 2014(Updated: )
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8017 is rated as a medium severity vulnerability.
To fix CVE-2014-8017, apply the latest patches provided by Cisco for the Identity Services Engine software.
CVE-2014-8017 is an information disclosure vulnerability affecting the periodic-backup feature.
CVE-2014-8017 affects users of Cisco Identity Services Engine software that utilize the periodic-backup feature.
Yes, CVE-2014-8017 can be exploited remotely by attackers sending crafted requests.