CVE-2015-6323
published 2016-01-15CVE-2015-6323: The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows…
PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.02%
85.9th percentile
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_unauthorized_access | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Unauthorized Access Vulnerability
vendor_cisco·2016-01-14·CVSS 10.0
CVE-2015-6323 [CRITICAL] CWE-287 Cisco Identity Services Engine Unauthorized Access Vulnerability
Cisco Identity Services Engine Unauthorized Access Vulnerability
A vulnerability in the Admin portal of devices running Cisco Identity Services Engine (ISE) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device.
An attacker who can connect to the Admin portal of an affected device could potentially exploit this vulnerability. A successful exploit may result in a complete compromise of the affected device. Customers are advised to apply a patch or upgrade to a version of Cisco ISE software that resolves this vulnerability.
Cisco has released software updates that address this vulnerability.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/secur
Cisco
Cisco Identity Services Engine Unauthorized Access Vulnerability
vendor_cisco
CVE-2015-6323 Cisco Identity Services Engine Unauthorized Access Vulnerability
CVE-2015-6323: Cisco Identity Services Engine Unauthorized Access Vulnerability
A vulnerability in the Admin portal of devices running Cisco Identity Services Engine (ISE) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. An attacker who can connect to the Admin portal of an affected device could potentially exploit this vulnerability. A successful exploit may result in a complete compromise of the affected device. Customers are advised to apply a patch or upgrade to a version of Cisco ISE software that resolves this vulnerability. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-287, CWE-287
Bug IDs: CSCuw34253
GHSA
GHSA-476p-q5r3-g7xv: The Admin portal in Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2015-6323 [CRITICAL] GHSA-476p-q5r3-g7xv: The Admin portal in Cisco Identity Services Engine (ISE) 1
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-01-15
Published