CVE-2015-4219
published 2015-06-24CVE-2015-4219: Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access…
PriorityP422medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.06%
79.2th percentile
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
| cisco | secure_access_control_system | <= 5.4.0.46.1 | — |
| cisco | secure_access_control_system | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine and Secure Access Control System Support Bundle Download Vulnerability
vendor_cisco·2015-06-23·CVSS 4.0
CVE-2015-4219 [MEDIUM] CWE-264 Cisco Identity Services Engine and Secure Access Control System Support Bundle Download Vulnerability
Cisco Identity Services Engine and Secure Access Control System Support Bundle Download Vulnerability
A vulnerability in Cisco Identity Services Engine and Secure Access Control System could allow an authenticated, remote attacker to gain unauthorized access to program data.
The vulnerability is due to weak authentication and authorization used to control access to support bundles stored on a targeted device. An authenticated, remote attacker could exploit the vulnerability through brute-force authentication attacks. If successful, the attacker could download files contained within the support bundle, possibly resulting in information disclosure.
Cisco has confirmed the vulnerability and released software updates.
The contents of the support bundle determine the overall impact of any
GHSA
GHSA-82xm-9qhp-mf4g: Cisco Secure Access Control System before 5
ghsa_unreviewed·2022-05-17
CVE-2015-4219 [MEDIUM] CWE-200 GHSA-82xm-9qhp-mf4g: Cisco Secure Access Control System before 5
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/viewAlert.x?alertId=39501http://www.securityfocus.com/bid/75379http://www.securitytracker.com/id/1032713http://www.securitytracker.com/id/1032714http://tools.cisco.com/security/center/viewAlert.x?alertId=39501http://www.securityfocus.com/bid/75379http://www.securitytracker.com/id/1032713http://www.securitytracker.com/id/1032714
2015-06-24
Published