CVE-2015-4267: CSRF
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus09940.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4267?
CVE-2015-4267 has a medium severity rating due to its potential to allow unauthorized user authentication hijacking.
How do I fix CVE-2015-4267?
To fix CVE-2015-4267, apply the recommended patches or updates provided by Cisco for the affected versions of the Identity Services Engine.
What impacts does CVE-2015-4267 have on my system?
CVE-2015-4267 can allow remote attackers to perform cross-site request forgery attacks, potentially compromising user accounts.
Which versions of Cisco Identity Services Engine are affected by CVE-2015-4267?
CVE-2015-4267 affects Cisco Identity Services Engine versions 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169).
Is there any workaround for CVE-2015-4267?
Currently, the recommended mitigation for CVE-2015-4267 is to upgrade to a patched version of the Cisco Identity Services Engine.