QID 317078
Date Published: 2021-11-15
QID 317078: Cisco Identity Services Engine (ISE) Local File Inclusion Vulnerability ( cisco-sa-ade-xcvAQEOZ)
A vulnerability in the restricted shell of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to identify directories and write arbitrary files to the file system.
Affected Versions:
For ISE
Prior to 2.6 Patch10
Prior to 2.7 Patch4
Prior to 3.0 Patch2
A successful exploit could allow the attacker to identify file directories on the affected device and write arbitrary files to the file system on the affected device.
Solution
Customers are advised to refer to cisco-sa-ade-xcvAQEOZ for more information.
Vendor References
- cisco-sa-ade-xcvAQEOZ -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ade-xcvAQEOZ
CVEs related to QID 317078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ade-xcvAQEOZ |
|