QID 317247
Date Published: 2022-11-02
QID 317247: Cisco Identity Services Engine (ISE) Unauthorized File Access Vulnerability (cisco-sa-ise-path-trav-Dz5dpzyM)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device.
Affected Products
Cisco ISE following vulnerable versions:
From 3.1 Prior to 3.1P5
From 3.2 Prior to 3.2P1
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to read or delete specific files on the device that their configured administrative level should not have access to.
Solution
Customers are advised to refer to cisco-sa-ise-path-trav-Dz5dpzyM for more information.
Vendor References
- cisco-sa-ise-path-trav-Dz5dpzyM -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM
CVEs related to QID 317247
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-path-trav-Dz5dpzyM |
|