← Back

CVE-2020-3467

nvd nist
Published: Oct 8, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.1 / Impact: 4.0
Source: NVD

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. The vulnerability is due to improper enforcement of role-based access control (RBAC) within the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to modify parts of the configuration. The modified configuration could either allow unauthorized devices onto the network or prevent authorized devices from accessing the network. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.

Affected (25)

1 product
Identity Services Engine
Configuration A
25 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 2.4
Version 2.4.0.357 patch10
Version 2.4.0.357 patch11
Version 2.4.0.357 patch12
Version 2.4.0.357 patch1
Version 2.4.0.357 patch2
Version 2.4.0.357 patch3
Version 2.4.0.357 patch4
Version 2.4.0.357 patch5
Version 2.4.0.357 patch6
Version 2.4.0.357 patch7
Version 2.4.0.357 patch8
Version 2.4.0.357 patch9
Version 2.4(0.357)
Version 2.5
Version 2.6.0.156 patch1
Version 2.6.0.156 patch2
Version 2.6.0.156 patch3
Version 2.6.0.156 patch5
Version 2.6.0.156 patch6
Version 2.6.0
Version 2.6(0.156)
Version 2.7.0.356 patch1
Version 2.7
Version 2.7(0.356)

Timeline

No history available yet.