9.8
CVSSv3

CVE-2017-6747

Published: 07/08/2017 Updated: 09/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote malicious user to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenticating with a valid external user account that matches an internal username and incorrectly receiving the authorization policy of the internal account. An exploit could allow the malicious user to have Super Admin privileges for the ISE Admin portal. This vulnerability does not affect endpoints authenticating to the ISE. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance running Release 1.3, 1.4, 2.0.0, 2.0.1, or 2.1.0. Release 2.2.x is not affected. Cisco Bug IDs: CSCvb10995.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine 1.4\\(0.253\\)

cisco identity services engine 2.0\\(1.130\\)

cisco identity services engine 2.1\\(0.474\\)

cisco identity services engine 1.4\\(0.109\\)

cisco identity services engine 1.4\\(0.181\\)

cisco identity services engine 2.1_base

cisco identity services engine 1.3\\(106.146\\)

cisco identity services engine 2.0_base

cisco identity services engine 1.3\\(0.722\\)

cisco identity services engine 1.4\\(0.908\\)

cisco identity services engine 1.3\\(0.876\\)

cisco identity services engine 2.1\\(0.800\\)

cisco identity services engine 1.3\\(0.909\\)

cisco identity services engine 2.0\\(0.222\\)

cisco identity services engine 2.1\\(102.101\\)

cisco identity services engine 2.0\\(0.147\\)

cisco identity services engine 1.3\\(120.135\\)

cisco identity services engine 2.0\\(0.169\\)

Vendor Advisories

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users An attacker could exploit this vulnerability by authe ...