CVE-2012-3908
published 2012-09-16CVE-2012-3908: Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.64%
46.5th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvch-jg7v-pvrx: Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity
ghsa_unreviewed·2022-05-17
CVE-2012-3908 [MEDIUM] CWE-352 GHSA-mvch-jg7v-pvrx: Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
Cisco
Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
vendor_cisco·2012-09-20·CVSS 6.8
CVE-2012-3908 [MEDIUM] CWE-352 Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
Cisco Identity Services Engine contains multiple vulnerabilities that could allow an unauthenticated, remote attacker to conduct cross-site request forgery attacks on a targeted system.
The vulnerability is due to insufficient sanitization of user-supplied input processed by the ISE Administrator user interface of the affected software. An unauthenticated, remote attacker could exploit this vulnerability by convincing an authorized user to follow a malicious link. Successful exploitation could allow the attacker to gain unauthorized access to the affected application, which could be used to conduct further attacks.
Cisco has confirmed the vulnerability in software release notes and released software updates.
To ex
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://en.securitylab.ru/lab/http://secunia.com/advisories/50680http://www.cisco.com/en/US/docs/security/ise/1.1/release_notes/ise1.1_rn.htmlhttp://www.securityfocus.com/bid/55602http://en.securitylab.ru/lab/http://secunia.com/advisories/50680http://www.cisco.com/en/US/docs/security/ise/1.1/release_notes/ise1.1_rn.htmlhttp://www.securityfocus.com/bid/55602
2012-09-16
Published