CVE-2014-8017

Description

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.

Risk Information

Base Score
5.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.152

Associated Vulnerability

VulnerabilityOS Platform
Cisco Identity Services Engine Periodic Backup Password Disclosure Vulnerability For Cisco Identity Services EngineNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-8017)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706002Security Update for Cisco Identity Services Engine 2.0(0.905)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234