5
CVSSv2

CVE-2014-8017

Published: 22/12/2014 Updated: 03/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote malicious users to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine software -

Vendor Advisories

A vulnerability in the periodic backup functionality of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to discover the password used to encrypt the backup on the system The vulnerability is due to improper processing of certain client requests by the affected software An attacker could exploit this vulnerabi ...