PT-2021-7256 · Cisco · Cisco Identity Services Engine
Published
2021-11-02
·
Updated
2023-07-24
·
CVE-2022-20733
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (ISE) (affected versions not specified)
Description
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This issue is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this by using the exposed SAML metadata to bypass authentication to the user portal, potentially accessing all roles without restrictions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Identity Services Engine