Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
BID:49703
Info
Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
| Bugtraq ID: | 49703 |
| Class: | Design Error |
| CVE: |
CVE-2011-3290 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2011 12:00AM |
| Updated: | Oct 03 2011 05:50PM |
| Credit: | Andrey Ovrashko and Sergey Bondarenko of BMS Consulting. |
| Vulnerable: |
Cisco Identity Services Engine 1.0.4 |
| Not Vulnerable: |
Cisco Identity Services Engine 1.0.4.MR2 |
Discussion
Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
Cisco Identity Services Engine is prone to a vulnerability that allows attackers to bypass certain security restrictions.
An attacker can exploit this issue to modify the device configuration and settings or gain complete administrative control of the device.
Cisco Identity Services Engine is prone to a vulnerability that allows attackers to bypass certain security restrictions.
An attacker can exploit this issue to modify the device configuration and settings or gain complete administrative control of the device.
Exploit / POC
Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Cisco Identity Services Engine Database Default Credentials Security Bypass Vulnerability
References:
References: