CVE-2013-5530
published 2013-10-25CVE-2013-5530: The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before…
PriorityP351critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.29%
81.2th percentile
The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443, aka Bug ID CSCuh81511.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r76p-vrmc-rm5f: The web framework in Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2013-5530 [HIGH] CWE-78 GHSA-r76p-vrmc-rm5f: The web framework in Cisco Identity Services Engine (ISE) 1
The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443, aka Bug ID CSCuh81511.
Cisco
Multiple Vulnerabilities in Cisco Identity Services Engine
vendor_cisco·2013-10-23·CVSS 9.0
CVE-2013-5530 [CRITICAL] CWE-20 Multiple Vulnerabilities in Cisco Identity Services Engine
Multiple Vulnerabilities in Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) contains the following vulnerabilities:
Cisco ISE Authenticated Arbitrary Command Execution Vulnerability
Cisco ISE Support Information Download Authentication Bypass Vulnerability
These vulnerabilities are independent of each other; a release that is
affected by one of the vulnerabilities may not be affected by the
other.
Successful exploitation of Cisco ISE Authenticated Arbitrary Command Execution Vulnerability may allow an authenticated remote
attacker to execute arbitrary code on the underlying operating system.
Successful
exploitation of Cisco ISE Support Information Download Authentication Bypass Vulnerability could allow an attacker to obtain
sensitive information including administ
Cisco
Multiple Vulnerabilities in Cisco Identity Services Engine
vendor_cisco
CVE-2013-5530 Multiple Vulnerabilities in Cisco Identity Services Engine
CVE-2013-5530: Multiple Vulnerabilities in Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) contains the following vulnerabilities: Cisco ISE Authenticated Arbitrary Command Execution Vulnerability Cisco ISE Support Information Download Authentication Bypass Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Successful exploitation of Cisco ISE Authenticated Arbitrary Command Execution Vulnerability may allow an authenticated remote attacker to execute arbitrary code on the underlying operating system. Successful exploitation of Cisco ISE Support Information Download Authentication Bypass Vulnerability could allow an attacker to obtain sensitive information includin
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-10-25
Published