First published: Wed Oct 02 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =2.7.0-p8 | |
Cisco Identity Services Engine | =3.0.0 | |
Cisco Identity Services Engine | =3.0.0-p1 | |
Cisco Identity Services Engine | =3.0.0-p2 | |
Cisco Identity Services Engine | =3.0.0-p3 | |
Cisco Identity Services Engine | =3.0.0-p4 | |
Cisco Identity Services Engine | =3.0.0-p5 | |
Cisco Identity Services Engine | =3.0.0-p6 | |
Cisco Identity Services Engine | =3.0.0-p7 | |
Cisco Identity Services Engine | =3.0.0-p8 | |
Cisco Identity Services Engine | =3.1.0 | |
Cisco Identity Services Engine | =3.1.0-p1 | |
Cisco Identity Services Engine | =3.1.0-p2 | |
Cisco Identity Services Engine | =3.1.0-p3 | |
Cisco Identity Services Engine | =3.1.0-p4 | |
Cisco Identity Services Engine | =3.1.0-p5 | |
Cisco Identity Services Engine | =3.1.0-p6 | |
Cisco Identity Services Engine | =3.1.0-p7 | |
Cisco Identity Services Engine | =3.1.0-p8 | |
Cisco Identity Services Engine | =3.2.0 | |
Cisco Identity Services Engine | =3.2.0-p1 | |
Cisco Identity Services Engine | =3.2.0-p2 | |
Cisco Identity Services Engine | =3.2.0-p3 | |
Cisco Identity Services Engine | =3.2.0-p4 | |
Cisco Identity Services Engine | =3.2.0-p5 | |
Cisco Identity Services Engine | =3.2.0-p6 | |
Cisco Identity Services Engine | =3.3.0 | |
Cisco Identity Services Engine | =3.3.0-p1 | |
Cisco Identity Services Engine | =3.3.0-p2 | |
Cisco Identity Services Engine | =3.3.0-p3 | |
Cisco Identity Services Engine | =3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.