The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.
References
Link | Resource |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3471 | Vendor Advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=30524 | Vendor Advisory |
http://www.securitytracker.com/id/1028965 | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: cisco
Published: 2013-08-29T10:00:00
Updated: 2013-09-11T09:00:00
Reserved: 2013-05-06T00:00:00
Link: CVE-2013-3471
JSON object: View
NVD Information
Status : Analyzed
Published: 2013-08-29T12:07:54.037
Modified: 2016-11-04T19:52:23.177
Link: CVE-2013-3471
JSON object: View
Redhat Information
No data.
CWE