4.9
CVE-2022-20914
- EPSS 0.16%
- Veröffentlicht 10.08.2022 09:15:08
- Zuletzt bearbeitet 21.11.2024 06:43:48
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version >= 2.4.0 < 2.6.0
Cisco ≫ Identity Services Engine Version2.6.0 Update-
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch1
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch10
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch2
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch3
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch5
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch6
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch7
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch8
Cisco ≫ Identity Services Engine Version2.6.0 Updatepatch9
Cisco ≫ Identity Services Engine Version2.7.0 Update-
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch1
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch2
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch3
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch4
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch5
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch6
Cisco ≫ Identity Services Engine Version2.7.0 Updatepatch7
Cisco ≫ Identity Services Engine Version3.0.0 Update-
Cisco ≫ Identity Services Engine Version3.0.0 Updatepatch1
Cisco ≫ Identity Services Engine Version3.0.0 Updatepatch2
Cisco ≫ Identity Services Engine Version3.0.0 Updatepatch3
Cisco ≫ Identity Services Engine Version3.0.0 Updatepatch4
Cisco ≫ Identity Services Engine Version3.0.0 Updatepatch5
Cisco ≫ Identity Services Engine Version3.1 Update-
Cisco ≫ Identity Services Engine Version3.1 Updatepatch1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.16% | 0.369 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
psirt@cisco.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-549 Missing Password Field Masking
The product does not mask passwords during entry, increasing the potential for attackers to observe and capture passwords.