Cisco Identity Services Engine Information Disclosure Vulnerability
Cisco patched an ISE API flaw letting an authenticated administrator view sensitive data including hashed credentials via crafted API requests.
A vulnerability in the Cisco Identity Services Engine API allows an authenticated remote attacker with valid administrative credentials to view sensitive information, including hashed credentials usable in future attacks. The flaw is caused by insufficient validation of user-supplied API request parameters. Cisco has released software updates.
- Exploitation requires valid administrative credentials
- Exposed data includes hashed credentials reusable in further attacks
- Caused by insufficient validation of API request parameters
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks. Cisco has released software updates that address this vulnerability. There are no…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.