PT-2017-17218 · Cisco · Cisco Identity Services Engine
Published
2017-05-22
·
Updated
2019-10-03
·
CVE-2017-6653
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (ISE) version 2.1(0.474)
Description
A denial of service (DoS) condition can occur on an affected device due to insufficient TCP rate limiting protection on the GUI, allowing an unauthenticated, remote attacker to cause the ISE GUI to fail to respond to new or established connection requests. This can be exploited by sending a high rate of TCP connections to the GUI, causing it to stop responding while the high rate of connections is in progress.
Recommendations
For Cisco Identity Services Engine (ISE) version 2.1(0.474), consider implementing rate limiting on TCP connections to the GUI as a temporary workaround until a patch is available. Restrict access to the GUI to minimize the risk of exploitation.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Identity Services Engine