Cisco Mobility Services Engine (MSE) 8.0(110.0) allows remote authenticated users to discover the passwords of arbitrary users by (1) reading log files or (2) using an unspecified GUI feature, aka Bug ID CSCut24792.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=38007 | vendor advisory |
http://www.securitytracker.com/id/1031971 | vdb entry |