Cisco Identity Services Engine Authorization Bypass (cisco-sa-20200108-ise-auth-bypass)

medium Nessus Plugin ID 133864

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

An authentication bypass vulnerability exists in the web-based management component of Cisco Identity Services Engine due to insufficient validation of user-supplied URL input. An authenticated, remote attacker can exploit this, by submitting specially crafted URL to an affected host, to bypass authentication and gain access to sensitive information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvq67348.

See Also

http://www.nessus.org/u?c44d3d67

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvq67348

Plugin Details

Severity: Medium

ID: 133864

File Name: cisco-sa-20200108-ise-auth-bypass.nasl

Version: 1.12

Type: local

Family: CISCO

Published: 2/24/2020

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2019-15255

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 1/26/2020

Vulnerability Publication Date: 1/26/2020

Reference Information

CVE: CVE-2019-15255

CISCO-SA: cisco-sa-20200108-ise-auth-bypass

IAVA: 2019-A-0361-S

CISCO-BUG-ID: CSCvq67348