CVE-2015-6266
published 2015-08-28CVE-2015-6266: The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.59%
72.8th percentile
The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability
vendor_cisco·2015-08-27·CVSS 5.0
CVE-2015-6266 [MEDIUM] CWE-287 Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability
Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability
A vulnerability in the Cisco Identity Services Engine (ISE) guest portal could allow an unauthenticated, remote attacker to view a customized page on the guest portal.
The vulnerability is due to lack of access control for the uploaded HTML files. An attacker could exploit this vulnerability by crafting an HTTP request that points to the filename of the customized page.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, the attacker must send a crafted HTTP request to the filename of the customized page on the guest portal. The Cisco ISE guest portal is configured to use customized uploaded HTML files, making an exploit easier to accomplish. Env
GHSA
GHSA-9hx7-74mf-ww6x: The guest portal in Cisco Identity Services Engine (ISE) 3300 1
ghsa_unreviewed·2022-05-17
CVE-2015-6266 [MEDIUM] CWE-287 GHSA-9hx7-74mf-ww6x: The guest portal in Cisco Identity Services Engine (ISE) 3300 1
The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-28
Published