Vulnerability Details CVE-2013-5538
The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary files via a direct request, aka Bug ID CSCui67506.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2013-5538
-
cpe:2.3:a:cisco:identity_services_engine_software:-
-
cpe:2.3:h:cisco:identity_services_engine:-