Описание
The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCul83904.
The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCul83904.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0665
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90463
- http://osvdb.org/102118
- http://secunia.com/advisories/56439
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0665
- http://tools.cisco.com/security/center/viewAlert.x?alertId=32448
- http://www.securityfocus.com/bid/64939
- http://www.securitytracker.com/id/1029624
EPSS
CVE ID
Связанные уязвимости
The RBAC implementation in Cisco Identity Services Engine (ISE) Software does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCul83904.
EPSS