A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests.
Cisco Identity Services Engine Information Disclosure Vulnerability
About this summary. This is a short, independently written summary of an article first published by Cisco PSIRT. Cyber Security News did not report or verify the underlying story. Read the original: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu?vs_f=Cisco%20Security%20Advisory%26vs_cat%3DSecurity%20Intelligence%26vs_type%3DRSS%26vs_p%3DCisco%20Identity%20Services%20Engine%20Information%20Disclosure%20Vulnerability%26vs_k%3D1
Source attribution: headline and facts are from Cisco PSIRT (sec.cloudapps.cisco.com). Summary method: excerpt of the source description. See our source attribution policy and corrections policy.


