Cisco Prime Infrastructure Certificate Validation Vulnerability
Published Feb 21, 2019
7.4
HIGHCVSS 3.0
EPSS 0.85%
Description
A vulnerability in the Identity Services Engine (ISE) integration feature of Cisco Prime Infrastructure (PI) could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack against the Secure Sockets Layer (SSL) tunnel established between ISE and PI. The vulnerability is due to improper validation of the server SSL certificate when establishing the SSL tunnel with ISE. An attacker could exploit this vulnerability by using a crafted SSL certificate and could then intercept communications between the ISE and PI. A successful exploit could allow the attacker to view and alter potentially sensitive information that the ISE maintains about clients that are connected to the network. This vulnerability affects Cisco Prime Infrastructure Software Releases 2.2 through 3.4.0 when the PI server is integrated with ISE, which is disabled by default.
Affected products
-
- Version next of 2.2StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<3.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco Prime Infrastructure | n/a |
|
- ≥ 2.2 · ≤ 3.4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- http://www.securityfocus.com/bid/107092 vdb-entryx_refsource_BIDThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10216 Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-prime-validation vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107092 | vdb-entryx_refsource_BIDThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-10216 | Advisory | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-prime-validation | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.