QID 317213

Date Published: 2022-08-11

QID 317213: Cisco Identity Services Engine (ISE) Sensitive Information Disclosure Vulnerability (cisco-sa-ise-pwd-WH64AhQF)

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information.
Category is kept as a practice because we cannot "Determine Whether External Authentication Server is Configured" or not with detection.

Affected Products
Cisco ISE following vulnerable versions:
From 2.4 Prior to 2.6P11
From 2.7 Prior to 2.7P8
From 3.0 Prior to 3.0P6
From 3.1 Prior to 3.1P3
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ise-pwd-WH64AhQF for more information.

    CVEs related to QID 317213

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ise-pwd-WH64AhQF URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-pwd-WH64AhQF