Vulnerability Name: | CVE-2015-6266 (CCN-105917) | ||||||||
Assigned: | 2015-08-27 | ||||||||
Published: | 2015-08-27 | ||||||||
Updated: | 2017-09-20 | ||||||||
Summary: | The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-6266 Source: CCN Type: Cisco Vulnerability Alert 40691 Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability Source: CISCO Type: Vendor Advisory 20150827 Cisco Identity Services Engine Guest Portal Unauthorized Access Vulnerability Source: SECTRACK Type: UNKNOWN 1033405 Source: XF Type: UNKNOWN cisco-ise-cve20156266-info-disc(105917) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |