QID 317343
QID 317343: Cisco Identity Services Engine (ISE) Device Credential Information Disclosure Vulnerability (cisco-sa-ise-credentials-tkTO3h3)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information.
Affected Versions:
2.6 and earlier
from 2.7 prior to 2.7p10
from 3.0 prior to 3.0p8
from 3.1 prior to 3.1p7
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to access sensitive information, including device entry credentials, that could aid the attacker in further attacks.
Solution
Customers are advised to refer to cisco-sa-ise-credentials-tkTO3h3 for more information.
Vendor References
- cisco-sa-ise-credentials-tkTO3h3 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-credentials-tkTO3h3
CVEs related to QID 317343
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-credentials-tkTO3h3 |
|