A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to…
cisco·CWE-287·Published 2017-11-16
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Guest Portal login page. An exploit could allow the attacker to perform brute-force password attacks on the ISE Guest Portal. Cisco Bug IDs: CSCve98518.
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side login attempt limit enforcement. An attacker could exploit this vulnerability by sending modified login attempts to the Guest Portal login page. An exploit could allow the attacker to perform brute-force password attacks on the ISE Guest Portal. Cisco Bug IDs: CSCve98518.
Una vulnerabilidad en la página de inicio de sesión de Guest Portal en Cisco Identity Services Engine (ISE) podría permitir que un atacante remoto sin autenticar realice múltiples intentos de inicio de sesión excediendo el límite de intentos de inicio de sesión configurado. La vulnerabilidad se debe a la aplicación insuficiente de límite de inicios de sesión del lado del servidor. Un atacante podría explotar esta vulnerabilidad enviando intentos de inicio de sesión modificados a la página de inicio de sesión de Guest Portal. Un exploit podría permitir que el atacante lleve a cabo ataques de contraseña por fuerza bruta en el Guest Portal de ISE. Cisco Bug IDs: CSCve98518.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 5.0 | 10.0 | 2.9 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| 3.0 | Primary | NVD | 7.5 | 3.9 | 3.6 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |