Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1659

Опубликовано: 21 фев. 2019
Источник: nvd
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI. The vulnerability is due to improper validation of the server SSL certificate when establishing the SSL tunnel with ISE. An attacker could exploit this vulnerability by using a crafted SSL certificate and could then intercept communications between the ISE and PI. A successful exploit could allow the attacker to view and alter potentially sensitive information that the ISE maintains about clients that are connected to the network. This vulnerability affects Cisco Prime Infrastructure Software Releases 2.2 through 3.4.0 when the PI server is integrated with ISE, which is disabled by default.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:prime_infrastructure:*:*:*:*:*:*:*:*
Версия от 2.2 (включая) до 3.4.0 (включая)

EPSS

Процентиль: 41%
0.0019
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 7.4
github
больше 3 лет назад

A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI. The vulnerability is due to improper validation of the server SSL certificate when establishing the SSL tunnel with ISE. An attacker could exploit this vulnerability by using a crafted SSL certificate and could then intercept communications between the ISE and PI. A successful exploit could allow the attacker to view and alter potentially sensitive information that the ISE maintains about clients that are connected to the network. This vulnerability affects Cisco Prime Infrastructure Software Releases 2.2 through 3.4.0 when the PI server is integrated with ISE, which is disabled by default.

CVSS3: 7.4
fstec
почти 7 лет назад

Уязвимость платформы управления политиками соединений Identity Services Engine системы мониторинга и управления сетевым оборудованием Cisco Prime Infrastructure, позволяющая нарушителю осуществить атаку типа «человек посередине»

EPSS

Процентиль: 41%
0.0019
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295