QID 317254
Date Published: 2022-11-09
QID 317254: Cisco Identity Services Engine (ISE) Cross-Site Request Forgery (CSRF) Vulnerability (cisco-sa-ise-csrf-vgNtTpAs)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
Affected Versions:
2.4 and earlier
from 2.6 Prior to 2.6p12
from 2.7 Prior to 2.7p8
from 3.0 Prior to 3.0p6
from 3.1 Prior to 3.1p4
from 3.1 Prior to 3.1p4
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the target user.
Customers are advised to refer to cisco-sa-ise-csrf-vgNtTpAs for more information.
- cisco-sa-ise-csrf-vgNtTpAs -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-csrf-vgNtTpAs
CVEs related to QID 317254
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-csrf-vgNtTpAs |
|