Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
BID:71767
Info
Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
| Bugtraq ID: | 71767 |
| Class: | Design Error |
| CVE: |
CVE-2014-8017 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2014 12:00AM |
| Updated: | Jan 12 2015 09:03AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
Cisco Identity Services Engine Software is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
This issue being tracked by Cisco Bug ID CSCur41673.
Cisco Identity Services Engine Software is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may lead to further attacks.
This issue being tracked by Cisco Bug ID CSCur41673.
Exploit / POC
Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
An attacker can exploit this issue using browser or readily available tools.
An attacker can exploit this issue using browser or readily available tools.
Solution / Fix
Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Identity Services Engine Software CVE-2014-8017 Password Disclosure Vulnerability
References:
References:
- Cisco Homepage (Cisco )