5.5
CVSSv2

CVE-2015-4182

Published: 12/06/2015 Updated: 04/01/2017
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

The administrative web interface in Cisco Identity Services Engine (ISE) prior to 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine software 1.2\\(0.747\\)

cisco identity services engine software 1.2\\(0.899\\)

cisco identity services engine software 1.2\\(1.901\\)

cisco identity services engine software 1.3

cisco identity services engine software 1.1

cisco identity services engine software 1.0.4.573

cisco identity services engine software 1.0_base

cisco identity services engine software 1.2

cisco identity services engine software 1.4

Vendor Advisories

A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or modify certain device settings The vulnerability is due to improper controls on certain pages in the web interface An attacker with authenticated access to the administrative ...