CVE-2022-20965

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface.

 This vulnerability is due to improper access control on a feature within the web-based management interface of the affected system. An attacker could exploit this vulnerability by accessing features through direct requests, bypassing checks within the application. A successful exploit could allow the attacker to take privileged actions within the web-based management interface that should be otherwise restricted.

    

  {{value}} ["%7b%7bvalue%7d%7d"])}]]
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
ciscoCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
ciscoidentity_services_engine
𝑥
< 2.6.0
ciscoidentity_services_engine
2.6.0
ciscoidentity_services_engine
2.6.0:patch1
ciscoidentity_services_engine
2.6.0:patch10
ciscoidentity_services_engine
2.6.0:patch11
ciscoidentity_services_engine
2.6.0:patch12
ciscoidentity_services_engine
2.6.0:patch2
ciscoidentity_services_engine
2.6.0:patch3
ciscoidentity_services_engine
2.6.0:patch5
ciscoidentity_services_engine
2.6.0:patch6
ciscoidentity_services_engine
2.6.0:patch7
ciscoidentity_services_engine
2.6.0:patch8
ciscoidentity_services_engine
2.6.0:patch9
ciscoidentity_services_engine
2.7.0
ciscoidentity_services_engine
2.7.0:patch1
ciscoidentity_services_engine
2.7.0:patch2
ciscoidentity_services_engine
2.7.0:patch3
ciscoidentity_services_engine
2.7.0:patch4
ciscoidentity_services_engine
2.7.0:patch5
ciscoidentity_services_engine
2.7.0:patch6
ciscoidentity_services_engine
2.7.0:patch7
ciscoidentity_services_engine
3.0.0
ciscoidentity_services_engine
3.0.0:patch1
ciscoidentity_services_engine
3.0.0:patch2
ciscoidentity_services_engine
3.0.0:patch3
ciscoidentity_services_engine
3.0.0:patch4
ciscoidentity_services_engine
3.0.0:patch5
ciscoidentity_services_engine
3.0.0:patch6
ciscoidentity_services_engine
3.1
ciscoidentity_services_engine
3.1:patch1
ciscoidentity_services_engine
3.1:patch3
ciscoidentity_services_engine
3.1:patch4
ciscoidentity_services_engine
3.2
𝑥
= Vulnerable software versions