CVE-2024-20515
MEDIUMDescription
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator privileges could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to view device credentials that are normally not visible to Read-Only Administrators.
Is your site exposed to CVE-2024-20515?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
References
Frequently Asked Questions
What is CVE-2024-20515? +
How severe is CVE-2024-20515? +
What products are affected by CVE-2024-20515? +
How do I check if I'm vulnerable to CVE-2024-20515? +
Related Vulnerabilities
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy …
Encryption is missing on the configuration interface for Growatt ShineLan-X and MIC 3300TL-X. This allows an attacker with access to …
Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT …
ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the …
Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.
Sensitive customer information is stored in the device without encryption.