CVE-2011-3290
published 2011-09-21CVE-2011-3290: Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.28%
81.1th percentile
Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_database_default_credentials | — | — |
| cisco | identity_services_engine_software | <= 1.0.4 | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Database Default Credentials Vulnerability
vendor_cisco
CVE-2011-3290 Cisco Identity Services Engine Database Default Credentials Vulnerability
CVE-2011-3290: Cisco Identity Services Engine Database Default Credentials Vulnerability
Cisco Identity Services Engine (ISE) contains a set of default credentials for its underlying database. A remote attacker could use those credentials to modify the device configuration and settings or gain complete administrative control of the device. Cisco has released software updates that address this vulnerability. There is no workaround for this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110920-ise .
Bug IDs: CSCts59135
GHSA
GHSA-rccw-f2p8-cj94: Cisco Identity Services Engine (ISE) before 1
ghsa_unreviewed·2022-05-17
CVE-2011-3290 [HIGH] GHSA-rccw-f2p8-cj94: Cisco Identity Services Engine (ISE) before 1
Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/46061http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtmlhttp://www.securityfocus.com/bid/49703http://www.securitytracker.com/id?1026075https://exchange.xforce.ibmcloud.com/vulnerabilities/69945http://secunia.com/advisories/46061http://www.cisco.com/en/US/products/products_security_advisory09186a0080b95105.shtmlhttp://www.securityfocus.com/bid/49703http://www.securitytracker.com/id?1026075https://exchange.xforce.ibmcloud.com/vulnerabilities/69945
2011-09-21
Published