CVE-2015-6317 - CVE House
Back to Database
Status published Medium CVE-2015-6317

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated...

Vulnerability Description

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-6317

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

identity services engine software
Vulnerable Versions:
1.0.4.573, 1.0_base, 1.0_mr_base, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1_base, 1.2\(0.747\), 1.2\(0.793\), 1.2\(1.198\), 1.2\(1.901\), 1.2.0.899, 1.2.1, 1.2_base, 1.3\(0.722\), 1.3\(0.876\), 1.3\(106.146\), 1.3\(120.135\), 1.4\(0.109\), 1.4\(0.181\), 1.4\(0.253\)

Timeline

Official Publish: January 23rd, 2016
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.