Learn about CVE-2021-40123, a vulnerability in Cisco Identity Services Engine Software allowing remote attackers to download restricted files. Find mitigation steps here.
Cisco Identity Services Engine Software has a vulnerability that allows an authenticated, remote attacker to download restricted files.
Understanding CVE-2021-40123
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an attacker to download restricted files.
What is CVE-2021-40123?
The issue arises due to incorrect permissions settings on the affected device, enabling an attacker with administrative read-only privileges to send a crafted HTTP request and retrieve restricted files.
The Impact of CVE-2021-40123
The base score for this vulnerability is 4.3, with a medium severity level. The attacker can exploit the vulnerability without user interaction and compromise confidentiality.
Technical Details of CVE-2021-40123
The following technical details describe the vulnerability in Cisco Identity Services Engine Software.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
The attacker, after gaining authenticated access with administrative read-only privileges, sends a crafted HTTP request to the device, taking advantage of incorrect permissions settings.
Mitigation and Prevention
Steps to address and prevent exploitation of CVE-2021-40123.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates