Description
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9Complexity: Low
Integrity: None
Availability: None
Affected Packages1 packages
🔴Vulnerability Details
4GHSAGHSA-9f58-w643-6379: The web framework in Cisco Identity Services Engine (ISE) 1↗2022-05-17 ▶ GHSAOpenStack Image Service (Glance) vulnerable to Improper Access Control↗2022-05-17 ▶ OSVglance vulnerabilities↗2017-10-11 ▶ CVEListCVE-2015-0757: The web framework in Cisco Identity Services Engine (ISE) 1↗2015-05-29 ▶ 💥Exploits & PoCs
1Exploit-DBSynology Video Station 1.5-0757 - Multiple Vulnerabilities↗2015-09-10 ▶ 📋Vendor Advisories
2Red Hatopenstack-glance: Glance image status manipulation through locations↗2016-02-04 ▶ CiscoCisco Identity Services Engine Information Disclosure Vulnerability↗2015-05-27 ▶