Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20733

Опубликовано: 15 июн. 2022
Источник: nvd
CVSS3: 5.3
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:identity_services_engine:3.1:-:*:*:*:*:*:*
cpe:2.3:a:cisco:identity_services_engine:3.1:patch1:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00518
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации

EPSS

Процентиль: 66%
0.00518
Низкий

5.3 Medium

CVSS3

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287
NVD-CWE-Other