A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability is due an issue in the authentication logic of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web interface. A successful exploit could allow the attacker to read a tcpdump file generated with a particular naming scheme.
History

Thu, 21 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2019-10-16T18:36:46.751554Z

Updated: 2024-11-21T19:06:36.677Z

Reserved: 2019-08-20T00:00:00

Link: CVE-2019-15282

cve-icon Vulnrichment

Updated: 2024-08-05T00:42:03.725Z

cve-icon NVD

Status : Modified

Published: 2019-10-16T19:15:15.583

Modified: 2024-11-21T04:28:22.273

Link: CVE-2019-15282

cve-icon Redhat

No data.