CVE-2011-3290
Summary
| CVE | CVE-2011-3290 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-09-21 16:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Identity Services Engine | All | All | All | All |
| Application | Cisco | Identity Services Engine Software | 1.0 | All | All | All |
| Application | Cisco | Identity Services Engine Software | 1.0mr | All | All | All |
| Application | Cisco | Identity Services Engine Software | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Security Advisory: Cisco Identity Services Engine Database Default Credentials Vulnerability - Cisco Systems | af854a3a-2127-422b-91ae-364da2661108 | www.cisco.com | Vendor Advisory |
| Cisco Identity Services Engine Undocumented Database Account Security Issue - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Cisco Identity Services Engine Default Credentials Let Remote Users Gain Administrative Access - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.