CVE-2015-6266 describes an information disclosure vulnerability in the guest portal of Cisco Identity Services Engine (ISE) 3300 1.2(0.899). This flaw allows unauthenticated remote attackers to directly access and retrieve sensitive information from custom HTML documents uploaded to the portal. The vulnerability has a CVSS score of 5.0, indicating a medium severity. It requires no authentication and has low attack complexity, potentially leading to the disclosure of confidential data without affecting integrity or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The CVE has received minimal community discussion and media coverage, suggesting a low profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2\(0.899\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_software:1.2\(0.899\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.