VulnerAlert



CISCO
CLOUD
MICROSOFT
ORACLE
04-06-2025 16:14

CVE-2025-20286 Vulnerabilidad documentada

9.9 CRITICAL
Tags
#exploit
#cross
#data
#web
#using
#form
#diff
#config
#azure
#admin
#oracle
#microsoft
#cloud
#cisco
#vulnerability
#systems
#affected
#improper
#authenticated
#remote
#execute
#configuration
#allow
#attack
#access
#affect
Descripción
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This exists because credentials are improperly generated when ISE is being deployed on platforms, resulting different sharing same credentials. These shared across multiple as long software release platform same. An exploit this by extracting user from that then using them other environments through unsecured ports. A successful systems. Note: If Primary Administration node cloud, affected vulnerability. on-premises, it not affected.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-20286
Resultados similares
Coincidentes en almenos en 50% de los tags
04-06-2025 CVE-2025-49008
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to versio...
Ver información
04-06-2025 CVE-2025-20279
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authe...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por