Vulnerability Name: | CVE-2015-4182 (CCN-103795) | ||||||||
Assigned: | 2015-06-11 | ||||||||
Published: | 2015-06-11 | ||||||||
Updated: | 2017-01-04 | ||||||||
Summary: | The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4182 Source: CCN Type: Cisco Vulnerability Alert 39299 Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability Source: CISCO Type: Vendor Advisory 20150611 Cisco Identity Services Engine Improper Web Page Controls Privilege Escalation Vulnerability Source: BID Type: Third Party Advisory, VDB Entry 75152 Source: SECTRACK Type: Third Party Advisory, VDB Entry 1032579 Source: XF Type: UNKNOWN cisco-ise-cve20154182-priv-esc(103795) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |