Vulnslist

find the latest Cisco vulnerabilities

Cisco Mobility Services Engine Control And Provisioning Information Disclosure Vulnerability

Cisco-SA-20150710-CVE-2015-4263 · Medium · Published · Updated

A vulnerability in the Control And Provisioning of the Cisco Mobility Services Engine (MSE) could allow an authenticated, remote attacker to have read access to sensitive information stored on an affected system. The vulnerability is due to the inclusion of sensitive information in certain log files. An attacker could exploit this by viewing the sensitive information stored in the vulnerable log files. Cisco has confirmed the vulnerability; however, software updates are not available. To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement decreases the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-4263
Cisco Bug IDsCSCut36851
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:P/I:N/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Mobility Services Engine

Related Products

Product CVE Evidence
Cisco Mobility Services Engine CVE-2015-4263 Cisco OpenVuln