René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

115 lines
3.8 KiB
JSON

{
"id": "CVE-2015-4267",
"sourceIdentifier": "ykramarz@cisco.com",
"published": "2015-07-15T18:59:00.083",
"lastModified": "2016-12-28T16:54:03.407",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus09940."
},
{
"lang": "es",
"value": "Vulnerabilidad CSRF en el Framework Web en Cisco Identity Services Engine (ISE) 1.2 (0.793), 1.3 (0.876), 1.4 (0.109), 2.0 (0.147), y 2.0 (0.169) que permite a atacantes remotos secuestrar la autenticaci\u00f3n de usuarios arbitrarios, tambi\u00e9n conocido como Bug ID CSCus09940."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.2\\(0.793\\):*:*:*:*:*:*:*",
"matchCriteriaId": "02270440-39DC-4105-B54F-25CF15507461"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.3\\(0.876\\):*:*:*:*:*:*:*",
"matchCriteriaId": "0F0C8A13-77BB-4D48-99C1-6C16D6A13FA5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.4\\(0.181\\):*:*:*:*:*:*:*",
"matchCriteriaId": "CC32610B-2D09-4F85-A2A1-775E6A778A9C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.4\\(0.876\\):*:*:*:*:*:*:*",
"matchCriteriaId": "2B02FE98-8F56-4B41-8E4A-1604CF796791"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:2.0\\(0.147\\):*:*:*:*:*:*:*",
"matchCriteriaId": "B786B1C6-9772-4210-925F-A0381E6A01F8"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:2.0\\(0.169\\):*:*:*:*:*:*:*",
"matchCriteriaId": "74F92467-49F9-4727-8471-DA3F398F9BF4"
}
]
}
]
}
],
"references": [
{
"url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=39872",
"source": "ykramarz@cisco.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securitytracker.com/id/1032929",
"source": "ykramarz@cisco.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}