Information disclosure in Cisco Identity Services Engine (ISE) - CVE-2018-15456
Published: January 9, 2019 / Updated: January 10, 2019
Cisco Identity Services Engine (ISE)
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin Portal. A remote attacker with read or write access to the Admin Portal can browse to a page that contains sensitive data and recover passwords for unauthorized use and expose those accounts to further attack.