Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-3525


A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin portal. An attacker with read or write access to the Admin portal could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to recover passwords and expose those accounts to further attack.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.


Published

2024-11-18T16:15:07.127

Last Modified

2025-06-24T16:15:28.180

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco identity_services_engine 002.002\(000.916\) Yes
Application cisco identity_services_engine 002.003\(000.906\) Yes
Application cisco identity_services_engine 002.004\(000.911\) Yes
Application cisco identity_services_engine 002.006\(000.902\) Yes

References