CVE-2013-3471
Cisco Identity Services Engine Software - Cleartext Credential Exposure via Captive Portal Hidden Form Fields
Title source: llmDescription
The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3471
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1028965
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=30524
Scores
EPSS
0.0142
EPSS Percentile
70.1%
Details
CWE
CWE-255
Status
published
Products (1)
cisco/identity_services_engine_software
Published
Aug 29, 2013
Tracked Since
Feb 18, 2026