Логотип exploitDog
bind:CVE-2022-20733
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-20733

Количество 3

Количество 3

nvd логотип

CVE-2022-20733

больше 3 лет назад

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-gqhw-x424-g962

больше 3 лет назад

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2022-04305

больше 4 лет назад

Уязвимость платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-20733

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-gqhw-x424-g962

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-04305

Уязвимость платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации

CVSS3: 9.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу