6.8
CVSSv2

CVE-2013-5540

Published: 16/10/2013 Updated: 16/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

A vulnerability in the file upload management of Cisco Identity Services Engine (ISE) could allow an authenticated, remote malicious user to upload multiple files to a specific location of the filesystem and exhaust disk space. The vulnerability is due to insufficient management of filesystem free space. An attacker could exploit this vulnerability by uploading multiple files. An exploit could allow the malicious user to exhaust free disk space on the system, resulting in a denial of service (DoS) condition in which the administration interface becomes unresponsive. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, an attacker would need to authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity_services_engine_software -

cisco identity_services_engine -

Vendor Advisories

A vulnerability in the file upload management of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload multiple files to a specific location of the filesystem and exhaust disk space The vulnerability is due to insufficient management of filesystem free space An attacker could exploit this vulnerability by u ...