CVE Vulnerabilities

CVE-2022-20914

Insufficiently Protected Credentials

Published: Aug 10, 2022 | Modified: Nov 07, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to obtain sensitive information, including administrative credentials for an external authentication server. Note: To successfully exploit this vulnerability, the attacker must have valid ERS administrative credentials.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Identity_services_engine Cisco 2.4.0 (including) 2.6.0 (excluding)
Identity_services_engine Cisco 2.6.0 (including) 2.6.0 (including)
Identity_services_engine Cisco 2.6.0-patch1 (including) 2.6.0-patch1 (including)
Identity_services_engine Cisco 2.6.0-patch10 (including) 2.6.0-patch10 (including)
Identity_services_engine Cisco 2.6.0-patch2 (including) 2.6.0-patch2 (including)
Identity_services_engine Cisco 2.6.0-patch3 (including) 2.6.0-patch3 (including)
Identity_services_engine Cisco 2.6.0-patch5 (including) 2.6.0-patch5 (including)
Identity_services_engine Cisco 2.6.0-patch6 (including) 2.6.0-patch6 (including)
Identity_services_engine Cisco 2.6.0-patch7 (including) 2.6.0-patch7 (including)
Identity_services_engine Cisco 2.6.0-patch8 (including) 2.6.0-patch8 (including)
Identity_services_engine Cisco 2.6.0-patch9 (including) 2.6.0-patch9 (including)
Identity_services_engine Cisco 2.7.0 (including) 2.7.0 (including)
Identity_services_engine Cisco 2.7.0-patch1 (including) 2.7.0-patch1 (including)
Identity_services_engine Cisco 2.7.0-patch2 (including) 2.7.0-patch2 (including)
Identity_services_engine Cisco 2.7.0-patch3 (including) 2.7.0-patch3 (including)
Identity_services_engine Cisco 2.7.0-patch4 (including) 2.7.0-patch4 (including)
Identity_services_engine Cisco 2.7.0-patch5 (including) 2.7.0-patch5 (including)
Identity_services_engine Cisco 2.7.0-patch6 (including) 2.7.0-patch6 (including)
Identity_services_engine Cisco 2.7.0-patch7 (including) 2.7.0-patch7 (including)
Identity_services_engine Cisco 3.0.0 (including) 3.0.0 (including)
Identity_services_engine Cisco 3.0.0-patch1 (including) 3.0.0-patch1 (including)
Identity_services_engine Cisco 3.0.0-patch2 (including) 3.0.0-patch2 (including)
Identity_services_engine Cisco 3.0.0-patch3 (including) 3.0.0-patch3 (including)
Identity_services_engine Cisco 3.0.0-patch4 (including) 3.0.0-patch4 (including)
Identity_services_engine Cisco 3.0.0-patch5 (including) 3.0.0-patch5 (including)
Identity_services_engine Cisco 3.1 (including) 3.1 (including)
Identity_services_engine Cisco 3.1-patch1 (including) 3.1-patch1 (including)

Potential Mitigations

References