CVE-2018-0187: Cisco Identity Services Engine Privileged Account Sensitive Information Disclosure Vulnerability
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information. An attacker could exploit this vulnerability by logging into the web interface on a vulnerable system. An exploit could allow an attacker to obtain confidential information for privileged accounts. This information could then be used to impersonate or negatively impact the privileged account on the affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0187?
CVE-2018-0187 has a high severity rating due to its potential for exposing confidential information for privileged accounts.
How do I fix CVE-2018-0187?
To fix CVE-2018-0187, it is recommended to update to the latest version of Cisco Identity Services Engine that addresses this vulnerability.
Who is affected by CVE-2018-0187?
CVE-2018-0187 affects authenticated users of specific versions of Cisco Identity Services Engine 2.4(0.901) and 2.4(0.901.1).
What type of vulnerability is CVE-2018-0187?
CVE-2018-0187 is an information disclosure vulnerability that can allow an attacker to access confidential data.
Can CVE-2018-0187 be exploited remotely?
Yes, CVE-2018-0187 can be exploited by an authenticated remote attacker.