CVE-2015-4182
published 2015-06-12CVE-2015-4182: The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions…
PriorityP426medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
2.09%
79.4th percentile
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability
vendor_cisco·2015-06-11·CVSS 5.5
CVE-2015-4182 [MEDIUM] CWE-264 Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability
Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or modify certain device settings.
The vulnerability is due to improper controls on certain pages in the web interface. An attacker with authenticated access to the administrative web interface could access pages that should be restricted to a more privileged access roll.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.
Cisco indicates through the CV
GHSA
GHSA-977m-h3qq-3266: The administrative web interface in Cisco Identity Services Engine (ISE) before 1
ghsa_unreviewed·2022-05-17
CVE-2015-4182 [MEDIUM] GHSA-977m-h3qq-3266: The administrative web interface in Cisco Identity Services Engine (ISE) before 1
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-12
Published