MEDIUM · 4.0

CVE-2015-4219

Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows ...

Vulnerability Description

Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoIdentity Services Engine Software1.0.4.573
CiscoSecure Access Control System<= 5.4.0.46.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4219?

CVE-2015-4219 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows ...

How severe is CVE-2015-4219?

CVE-2015-4219 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4219?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Identity Services Engine Software, Cisco Secure Access Control System.