Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Identity Services Engine and Secure Access Control System Support Bundle Download Vulnerability

Cisco-SA-20150623-CVE-2015-4219 · Medium · Published · Updated

A vulnerability in Cisco Identity Services Engine and Secure Access Control System could allow an authenticated, remote attacker to gain unauthorized access to program data. The vulnerability is due to weak authentication and authorization used to control access to support bundles stored on a targeted device. An authenticated, remote attacker could exploit the vulnerability through brute-force authentication attacks. If successful, the attacker could download files contained within the support bundle, possibly resulting in information disclosure. Cisco has confirmed the vulnerability and released software updates. The contents of the support bundle determine the overall impact of any exploit. If the files within the support bundle contain confidential information, the attacker could use the information gained to conduct further attacks against a targeted system.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators may consider removing old or unneeded storage bundles from exposed devices.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-4219
Cisco Bug IDsCSCub40331, CSCue00833
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:P/I:N/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Secure Access Control System (ACS), Cisco Identity Services Engine Software

Related Products

Product CVE Evidence
Cisco Secure Access Control System (ACS) CVE-2015-4219 Cisco OpenVuln
Cisco Identity Services Engine Software CVE-2015-4219 Cisco OpenVuln