VulnerabilityModified
CVE-2013-3471
The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.
MEDIUM 4.3EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/identity services engine software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3471Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30524Vendor Advisory
- http://www.securitytracker.com/id/1028965Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3471Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=30524Vendor Advisory
- http://www.securitytracker.com/id/1028965Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.