CVE-2024-20515
02.10.2024, 17:15
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | identity_services_engine | 2.7.0:p8 |
cisco | identity_services_engine | 3.0.0 |
cisco | identity_services_engine | 3.0.0:p1 |
cisco | identity_services_engine | 3.0.0:p2 |
cisco | identity_services_engine | 3.0.0:p3 |
cisco | identity_services_engine | 3.0.0:p4 |
cisco | identity_services_engine | 3.0.0:p5 |
cisco | identity_services_engine | 3.0.0:p6 |
cisco | identity_services_engine | 3.0.0:p7 |
cisco | identity_services_engine | 3.0.0:p8 |
cisco | identity_services_engine | 3.1.0 |
cisco | identity_services_engine | 3.1.0:p1 |
cisco | identity_services_engine | 3.1.0:p2 |
cisco | identity_services_engine | 3.1.0:p3 |
cisco | identity_services_engine | 3.1.0:p4 |
cisco | identity_services_engine | 3.1.0:p5 |
cisco | identity_services_engine | 3.1.0:p6 |
cisco | identity_services_engine | 3.1.0:p7 |
cisco | identity_services_engine | 3.1.0:p8 |
cisco | identity_services_engine | 3.2.0 |
cisco | identity_services_engine | 3.2.0:p1 |
cisco | identity_services_engine | 3.2.0:p2 |
cisco | identity_services_engine | 3.2.0:p3 |
cisco | identity_services_engine | 3.2.0:p4 |
cisco | identity_services_engine | 3.2.0:p5 |
cisco | identity_services_engine | 3.2.0:p6 |
cisco | identity_services_engine | 3.3.0 |
cisco | identity_services_engine | 3.3.0:p1 |
cisco | identity_services_engine | 3.3.0:p2 |
cisco | identity_services_engine | 3.3.0:p3 |
cisco | identity_services_engine | 3.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration