CVE-2013-5531Improper Authentication in Cisco Identity Services Engine Software

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 51.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 17

Description

Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3mxh-57x7-m994: Cisco Identity Services Engine (ISE) 12022-05-17
CVEList
CVE-2013-5531: Cisco Identity Services Engine (ISE) 12013-10-25

📋Vendor Advisories

2
Cisco
Multiple Vulnerabilities in Cisco Identity Services Engine2013-10-23
Cisco
Cisco ISE Support Information Download Authentication Bypass Vulnerability2013-10-23

💬Community

1
Bugzilla
CVE-2012-5531 GateIn Portal: Reflected Cross-Site Scripting (XSS)2012-11-16
CVE-2013-5531 — Improper Authentication in Cisco | cvebase