Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities
Cisco patched Identity Services Engine flaws letting unauthenticated local attackers bypass 802.1X authentication or disclose sensitive information.
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated local attacker to conduct an authentication bypass involving 802.1X session hijack or disclose sensitive information. Cisco has released software updates addressing these vulnerabilities. No workarounds are available. The advisory is part of a batch of Cisco releases.
- Unauthenticated local attacker can bypass 802.1X authentication
- Sensitive information disclosure also possible
- Software updates released; no workarounds
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.