CVE-2021-40123: Cisco Identity Services Engine File Download Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incorrect permissions settings on an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the device. A successful exploit could allow the attacker to download files that should be restricted.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-40123.
Which software is affected by this vulnerability?
The Cisco Identity Services Engine (ISE) version 2.6 and later are affected.
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium with a CVSS score of 6.5.
How can an attacker exploit this vulnerability?
An authenticated, remote attacker with administrative read-only privileges can exploit this vulnerability to download restricted files.
Is there a fix available for this vulnerability?
Yes, Cisco has released a security advisory with detailed information and patches to address this vulnerability.