CVE-2017-12261
Summary
| CVE | CVE-2017-12261 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-02 16:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the restricted shell. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. An attacker would need valid user credentials to the device to exploit this vulnerability. The vulnerability affects the following Cisco Identity Services Engine (ISE) products running Release 1.4, 2.0, 2.0.1, 2.1.0: ISE, ISE Express, ISE Virtual Appliance. Cisco Bug IDs: CSCve74916. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-264 | CWE-863 | CWE-264 CWE-264
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.2 | AV:L/AC:L/Au:N/C:C/I:C/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Identity Services Engine | 1.4 | All | All | All |
| Application | Cisco | Identity Services Engine | 2.0 | All | All | All |
| Application | Cisco | Identity Services Engine | 2.0.1 | All | All | All |
| Application | Cisco | Identity Services Engine | 2.1.0 | All | All | All |
| Application | Cisco | Identity Services Engine Express | 1.4 | All | All | All |
| Application | Cisco | Identity Services Engine Express | 2.0 | All | All | All |
| Application | Cisco | Identity Services Engine Express | 2.0.1 | All | All | All |
| Application | Cisco | Identity Services Engine Express | 2.1.0 | All | All | All |
| Application | Cisco | Identity Services Engine Virtual Appliance | 1.4 | All | All | All |
| Application | Cisco | Identity Services Engine Virtual Appliance | 2.0 | All | All | All |
| Application | Cisco | Identity Services Engine Virtual Appliance | 2.0.1 | All | All | All |
| Application | Cisco | Identity Services Engine Virtual Appliance | 2.1.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Identity Services Engine | affected Cisco Identity Services Engine | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Identity Services Engine Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Identity Services Engine CLI Input Validation Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Cisco Identity Services Engine CVE-2017-12261 Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.