← Back

CVE-2022-20819

nvd nist
Published: Jun 15, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive data are not properly enforced. An attacker with read-only privileges for the web-based management interface on an affected device could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information about the system configuration.

Affected (17)

1 product
Identity Services Engine
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 2.4.0.357
From 2.6. to 2.6.0.156
From 2.7 to 2.7.0.305
Version 2.4.0.357
Version 2.4.0.357 patch10
Version 2.4.0.357 patch1
Version 2.4.0.357 patch2
Version 2.4.0.357 patch3
Version 2.4.0.357 patch4
Version 2.4.0.357 patch5
Version 2.4.0.357 patch6
Version 2.4.0.357 patch7
Version 2.4.0.357 patch8
Version 2.4.0.357 patch9
Version 2.6.0.156 patch1
Version 2.6.0.156 patch2
Version 2.6.0.156 patch3

Timeline

No history available yet.