Information disclosure in Cisco Identity Services Engine (ISE) - CVE-2018-0187

 

Information disclosure in Cisco Identity Services Engine (ISE) - CVE-2018-0187

Published: January 24, 2019


Vulnerability identifier: #VU17192
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0187
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists in the Admin portal due to improper handling of confidential information. A remote attacker can log into the web interface and obtain confidential information for privileged accounts that can then be used to impersonate or negatively impact the privileged account on the affected system.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2018-0187

The vulnerability has been addressed in the versions 2.4(0.904), 2.2(0.911).

Cisco Identity Services Engine (ISE) - addressed in versions 2.2.0.911, 2.4.0.904

External References

Related Security Bulletins