5
CVSSv2

CVE-2013-5538

Published: 16/10/2013 Updated: 16/10/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote malicious users to read arbitrary files via a direct request, aka Bug ID CSCui67506.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity_services_engine_software -

cisco identity_services_engine -

Vendor Advisories

A vulnerability in the Sponsor Portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access files uploaded to the Sponsor Portal The vulnerability is due to insufficient file permissions An attacker could exploit this vulnerability by accessing the URL that contains the Sponsor Portal files An exploit ...