5
CVSSv2

CVE-2013-5521

Published: 25/10/2013 Updated: 25/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote malicious users to cause a denial of service (exhaustion of the account supply) via a series of requests within one session, aka Bug ID CSCue94287.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine software -

Vendor Advisories

A vulnerability in Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to exhaust guest user account resources The vulnerability is due to a guest account creation page that allows unlimited guest accounts to be created upon refreshing the page An attacker could exploit this vulnerability by creating a new guest ...