Vulnerability Bulletins

Cisco Policy Suite Confidential Information Disclosure Vulnerability

   
Affected software Cisco
 
A vulnerability in password management administration of the Cisco Policy Suite (CPS) application could allow an unauthenticated, remote attacker to gain read-only access to information that is confidential and should have restricted access.The vulnerability is due to the lack of a proper role-based access control (RBAC) implementation. An attacker could exploit this vulnerability by remotely connecting to an affected Cisco CPS system. An exploit could allow the attacker to gain read-only

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-psc?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Policy%20Suite%20Confidential%20Information%20Disclosure%20Vulnerabili