QID 317165

Date Published: 2022-07-04

QID 317165: Cisco Identity Services Engine (ISE) Sensitive Information Disclosure Vulnerability (cisco-sa-info-exp-YXAWYP3s)

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE)
could allow an authenticated, remote attacker to obtain sensitive information from an affected device.

Affected Products
Cisco ISE following vulnerable versions:
From 2.3 Prior to 2.6P11 (May 2022)
From 2.7 Prior to 2.7P7
From 3.0 Prior to 3.0P05
From 3.1 Prior to 3.1P01
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to collect sensitive information regarding the configuration of the system.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-info-exp-YXAWYP3s for more information.

    CVEs related to QID 317165

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-info-exp-YXAWYP3s URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-info-exp-YXAWYP3s