CVE-2024-20515

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 2, 2024
Updated: Oct 8, 2024
CWE ID 311

Summary

CVE-2024-20515 is a vulnerability affecting Cisco Identity Services Engine (ISE) products, which allows an authenticated remote attacker to access sensitive information due to insufficient data protection for certain configuration settings. The issue can be exploited by users with Read-Only Administrator privileges who navigate to pages displaying sensitive data, potentially revealing device credentials typically hidden from their view. This vulnerability has a medium severity rating, with a CVSS base score of 6.5 and a confidentiality impact classified as high. Organizations are advised to implement available security updates from Cisco and review their access controls to mitigate this risk effectively. Failure to address this vulnerability may lead to unauthorized exposure of sensitive information within the network.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share