CVE-2020-3525
Description
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin portal. An attacker with read or write access to the Admin portal could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to recover passwords and expose those accounts to further attack.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:cisco:identity_services_engine:002.002\(000.916\):*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cisco:identity_services_engine:002.002\(000.916\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:002.003\(000.906\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:002.004\(000.911\):*:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:002.006\(000.902\):*:*:*:*:*:*:*
- (no CPE)range: N/A
Patches
Vulnerability mechanics
References
5- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-pass-disclosure-K8p2NsggnvdVendor Advisory
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-cuc-imp-xss-XtpzfM5envdNot Applicable
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-authbypass-YVJzqgk2nvdNot Applicable
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-dcnm-pa-trav-bMdfSTTqnvdNot Applicable
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-tls-dos-xW53TBhbnvdNot Applicable
News mentions
0No linked articles in our index yet.