CVE-2017-6747 describes a critical authentication bypass vulnerability in Cisco Identity Services Engine (ISE) versions 1.3, 1.4, 2.0.0, 2.0.1, and 2.1.0. An unauthenticated, remote attacker could exploit improper handling of authentication requests to gain Super Admin privileges by using a valid external user account that matches an internal username. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3\(0.722\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:1.3\(0.722\):*:*:*:*:*:*:* | ||
1.3\(0.876\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:1.3\(0.876\):*:*:*:*:*:*:* | ||
1.3\(0.909\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:1.3\(0.909\):*:*:*:*:*:*:* | ||
1.3\(106.146\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:1.3\(106.146\):*:*:*:*:*:*:* | ||
1.3\(120.135\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:1.3\(120.135\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.