Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1134

Опубликовано: 29 июн. 2021
Источник: nvd
CVSS3: 7.4
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the attacker to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия до 2.2.2.1 (исключая)

EPSS

Процентиль: 42%
0.00202
Низкий

7.4 High

CVSS3

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 7.4
github
больше 3 лет назад

A vulnerability in the Cisco Identity Services Engine (ISE) integration feature of the Cisco DNA Center Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to an incomplete validation of the X.509 certificate used when establishing a connection between DNA Center and an ISE server. An attacker could exploit this vulnerability by supplying a crafted certificate and could then intercept communications between the ISE and DNA Center. A successful exploit could allow the attacker to view and alter sensitive information that the ISE maintains about clients that are connected to the network.

CVSS3: 7.4
fstec
больше 4 лет назад

Уязвимость функции интеграции платформы управления политиками соединений Cisco Identity Services Engine системы управления сетью Cisco Digital Network Architecture (DNA) Center, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 42%
0.00202
Низкий

7.4 High

CVSS3

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295