Cisco Security Advisory - Cisco Identity Services Engine Administrator Password Lifetime Expiration Issue

Started by Netwörkheäd, July 21, 2022, 12:28:01 AM

Previous topic - Next topic

Netwörkheäd

Cisco Identity Services Engine Administrator Password Lifetime Expiration Issue

<p>An issue in the Password Policy settings of Cisco&nbsp;Identity Services Engine (ISE) could allow an administrator to use expired credentials to gain access to the web management interface.</p>
<p>When the Password Lifetime<strong> </strong>setting for the administrator password policy is used to set the password to expire, the password does not expire. As a result, an administrator could use expired credentials to log in to the web management interface and have the same level of privileges as before the password expired. No additional privileges would be gained, and valid credentials would be required.</p>
<p>This advisory is available at the following link:<br><a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-lifetime-pwd-GpCs76mb" target="_blank">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-lifetime-pwd-GpCs76mb</a></p>
     
         
Security Impact Rating:  Informational
Source: Cisco Identity Services Engine Administrator Password Lifetime Expiration Issue
Let's not argue. Let's network!