CVE-2024-20515

Cisco Identity Services Engine Information Disclosure Vulnerability

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.5th percentile
Discovered by
Third party
Vendor-published field
Published
Oct 2, 2024
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.

Weakness: CWE-311

Affected products

Vendor Product Category Matched by
Cisco Cisco Identity Services Engine (ISE) Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Identity Services Engine Software

Something wrong here?