QID 317070
Date Published: 2021-10-07
QID 317070: Cisco Identity Services Engine (ISE) Extensible Markup Language (XML) External Entity Injection Vulnerability ( cisco-sa-ise-xxe-inj-V4VSjEsX)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device.
Affected Versions:
Cisco ISE releases 3.1 and earlier.
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the web application to perform arbitrary HTTP requests on behalf of the attacker.
.
Customers are advised to refer to cisco-sa-ise-xxe-inj-V4VSjEsX for more information.
- cisco-sa-ise-xxe-inj-V4VSjEsX -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-V4VSjEsX
CVEs related to QID 317070
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-xxe-inj-V4VSjEsX |
|