CVE-2013-5531
published 2013-10-25CVE-2013-5531: Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.34%
68.0th percentile
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3mxh-57x7-m994: Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2013-5531 [MEDIUM] CWE-287 GHSA-3mxh-57x7-m994: Cisco Identity Services Engine (ISE) 1
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
Cisco
Multiple Vulnerabilities in Cisco Identity Services Engine
vendor_cisco·2013-10-23·CVSS 9.0
CVE-2013-5530 [CRITICAL] CWE-20 Multiple Vulnerabilities in Cisco Identity Services Engine
Multiple Vulnerabilities in Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) contains the following vulnerabilities:
Cisco ISE Authenticated Arbitrary Command Execution Vulnerability
Cisco ISE Support Information Download Authentication Bypass Vulnerability
These vulnerabilities are independent of each other; a release that is
affected by one of the vulnerabilities may not be affected by the
other.
Successful exploitation of Cisco ISE Authenticated Arbitrary Command Execution Vulnerability may allow an authenticated remote
attacker to execute arbitrary code on the underlying operating system.
Successful
exploitation of Cisco ISE Support Information Download Authentication Bypass Vulnerability could allow an attacker to obtain
sensitive information including administ
Cisco
Cisco ISE Support Information Download Authentication Bypass Vulnerability
vendor_cisco·2013-10-23·CVSS 5.0
CVE-2013-5531 [MEDIUM] CWE-20 Cisco ISE Support Information Download Authentication Bypass Vulnerability
Cisco ISE Support Information Download Authentication Bypass Vulnerability
A vulnerability in the implementation of the authentication code that is used to validate requests to download a product support bundle could allow an unauthenticated, remote attacker to download a full product support bundle.
The vulnerability is due to an error in the logic that is used to validate support bundle access requests. An attacker could exploit this vulnerability by sending a crafted request to the vulnerable system. An exploit could allow an attacker to obtain a full copy of the product configuration or other sensitive information including administrative credentials.
Cisco confirmed the vulnerability in a security advisory and released software updates.
A successful exploit could allow an attacke
Cisco
Multiple Vulnerabilities in Cisco Identity Services Engine
vendor_cisco
CVE-2013-5531 Multiple Vulnerabilities in Cisco Identity Services Engine
CVE-2013-5531: Multiple Vulnerabilities in Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) contains the following vulnerabilities: Cisco ISE Authenticated Arbitrary Command Execution Vulnerability Cisco ISE Support Information Download Authentication Bypass Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the other. Successful exploitation of Cisco ISE Authenticated Arbitrary Command Execution Vulnerability may allow an authenticated remote attacker to execute arbitrary code on the underlying operating system. Successful exploitation of Cisco ISE Support Information Download Authentication Bypass Vulnerability could allow an attacker to obtain sensitive information includin
No detection rules found.
No public exploits indexed.
2013-10-25
Published