CVE-2023-20111
Summary
| CVE | CVE-2023-20111 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-16 22:15:00 UTC |
| Updated | 2024-01-25 17:15:00 UTC |
| Description | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface and viewing hidden fields within the application. A successful exploit could allow the attacker to access sensitive information, including device entry credentials, that could aid the attacker in further attacks. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Identity Services Engine | 2.7.0 | - | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch1 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch2 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch3 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch4 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch5 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch6 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch7 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch8 | All | All |
| Application | Cisco | Identity Services Engine | 2.7.0 | patch9 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | - | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch1 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch2 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch3 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch4 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch5 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch6 | All | All |
| Application | Cisco | Identity Services Engine | 3.0.0 | patch7 | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | - | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | patch1 | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | patch3 | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | patch4 | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | patch5 | All | All |
| Application | Cisco | Identity Services Engine | 3.1 | patch6 | All | All |
| Application | Cisco | Identity Services Engine | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Identity Services Engine Device Credential Information Disclosure Vulnerability | MISC | sec.cloudapps.cisco.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 317343 Cisco Identity Services Engine (ISE) Device Credential Information Disclosure Vulnerability (cisco-sa-ise-credentials-tkTO3h3)