CVE-2024-20515: Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20515?
CVE-2024-20515 is rated as a medium-severity vulnerability.
How do I fix CVE-2024-20515?
To remediate CVE-2024-20515, upgrade to the latest version of Cisco Identity Services Engine as recommended by Cisco's security advisory.
What are the affected versions for CVE-2024-20515?
CVE-2024-20515 affects Cisco Identity Services Engine versions 2.7.0-p8, 3.0.0 through 3.4.0.
What type of attack does CVE-2024-20515 facilitate?
CVE-2024-20515 allows an authenticated, remote attacker to obtain sensitive information from affected devices.
Is authentication required to exploit CVE-2024-20515?
Yes, exploitation of CVE-2024-20515 requires valid authentication to the Cisco Identity Services Engine.