CVE-2015-4219

Severity
4.0MEDIUM
EPSS
0.4%
top 38.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 17

Description

Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-82xm-9qhp-mf4g: Cisco Secure Access Control System before 5โ†—2022-05-17
โ–ถ
CVEList
CVE-2015-4219: Cisco Secure Access Control System before 5โ†—2015-06-24
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Cisco
Cisco Identity Services Engine and Secure Access Control System Support Bundle Download Vulnerabilityโ†—2015-06-23
โ–ถ
CVE-2015-4219 (MEDIUM CVSS 4) | Cisco Secure Access Control System | cvebase.io