First published: Wed Oct 02 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) | =2.7.0-p8 | |
Cisco Identity Services Engine (ISE) | =3.0.0 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p1 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p2 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p3 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p4 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p5 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p6 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p7 | |
Cisco Identity Services Engine (ISE) | =3.0.0-p8 | |
Cisco Identity Services Engine (ISE) | =3.1.0 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p1 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p2 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p3 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p4 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p5 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p6 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p7 | |
Cisco Identity Services Engine (ISE) | =3.1.0-p8 | |
Cisco Identity Services Engine (ISE) | =3.2.0 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p1 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p2 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p3 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p4 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p5 | |
Cisco Identity Services Engine (ISE) | =3.2.0-p6 | |
Cisco Identity Services Engine (ISE) | =3.3.0 | |
Cisco Identity Services Engine (ISE) | =3.3.0-p1 | |
Cisco Identity Services Engine (ISE) | =3.3.0-p2 | |
Cisco Identity Services Engine (ISE) | =3.3.0-p3 | |
Cisco Identity Services Engine (ISE) | =3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20515 is rated as a medium-severity vulnerability.
To remediate CVE-2024-20515, upgrade to the latest version of Cisco Identity Services Engine as recommended by Cisco's security advisory.
CVE-2024-20515 affects Cisco Identity Services Engine versions 2.7.0-p8, 3.0.0 through 3.4.0.
CVE-2024-20515 allows an authenticated, remote attacker to obtain sensitive information from affected devices.
Yes, exploitation of CVE-2024-20515 requires valid authentication to the Cisco Identity Services Engine.