Description
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
CVSS breakdown
Affected products
- Cisco / Cisco Identity Services Engine Software3.0.0 – 3.0.0
- Cisco / Cisco Identity Services Engine Software3.0.0 p1 – 3.0.0 p1
- Cisco / Cisco Identity Services Engine Software3.0.0 p2 – 3.0.0 p2
- Cisco / Cisco Identity Services Engine Software3.0.0 p3 – 3.0.0 p3
- Cisco / Cisco Identity Services Engine Software3.1.0 – 3.1.0
- Cisco / Cisco Identity Services Engine Software3.0.0 p4 – 3.0.0 p4
- Cisco / Cisco Identity Services Engine Software3.1.0 p1 – 3.1.0 p1
- Cisco / Cisco Identity Services Engine Software3.0.0 p5 – 3.0.0 p5
- Cisco / Cisco Identity Services Engine Software3.1.0 p3 – 3.1.0 p3
- Cisco / Cisco Identity Services Engine Software3.1.0 p2 – 3.1.0 p2
- Cisco / Cisco Identity Services Engine Software3.0.0 p6 – 3.0.0 p6
- Cisco / Cisco Identity Services Engine Software3.2.0 – 3.2.0
- Cisco / Cisco Identity Services Engine Software3.1.0 p4 – 3.1.0 p4
- Cisco / Cisco Identity Services Engine Software2.7.0 p8 – 2.7.0 p8
- Cisco / Cisco Identity Services Engine Software3.1.0 p5 – 3.1.0 p5
- Cisco / Cisco Identity Services Engine Software3.2.0 p1 – 3.2.0 p1
- Cisco / Cisco Identity Services Engine Software3.0.0 p7 – 3.0.0 p7
- Cisco / Cisco Identity Services Engine Software3.1.0 p6 – 3.1.0 p6
- Cisco / Cisco Identity Services Engine Software3.2.0 p2 – 3.2.0 p2
- Cisco / Cisco Identity Services Engine Software3.1.0 p7 – 3.1.0 p7
- Cisco / Cisco Identity Services Engine Software3.3.0 – 3.3.0
- Cisco / Cisco Identity Services Engine Software3.2.0 p3 – 3.2.0 p3
- Cisco / Cisco Identity Services Engine Software3.0.0 p8 – 3.0.0 p8
- Cisco / Cisco Identity Services Engine Software3.2.0 p4 – 3.2.0 p4
- Cisco / Cisco Identity Services Engine Software3.1.0 p8 – 3.1.0 p8
- Cisco / Cisco Identity Services Engine Software3.2.0 p5 – 3.2.0 p5
- Cisco / Cisco Identity Services Engine Software3.2.0 p6 – 3.2.0 p6
- Cisco / Cisco Identity Services Engine Software3.1.0 p9 – 3.1.0 p9
- Cisco / Cisco Identity Services Engine Software3.3 Patch 2 – 3.3 Patch 2
- Cisco / Cisco Identity Services Engine Software3.3 Patch 1 – 3.3 Patch 1
- Cisco / Cisco Identity Services Engine Software3.3 Patch 3 – 3.3 Patch 3
- Cisco / Cisco ISE Passive Identity Connector3.0.0 – 3.0.0
- Cisco / Cisco ISE Passive Identity Connector3.2.0 – 3.2.0
- Cisco / Cisco ISE Passive Identity Connector3.1.0 – 3.1.0
- Cisco / Cisco ISE Passive Identity Connector3.3.0 – 3.3.0