QID 317276

Date Published: 2022-11-21

QID 317276: Cisco Identity Services Engine (ISE) Multiple Vulnerabilities (cisco-sa-ise-7Q4TNYUx)

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to inject arbitrary operating system commands, bypass security protections, and conduct cross-site scripting attacks.

Affected Products
Cisco ISE following vulnerable versions:
2.7 and earlier
3.0 and earlier
3.1 prior to 3.1p6
3.2 prior to 3.2p1
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.

Successful could allow an authenticated, remote attacker to inject arbitrary operating system commands, bypass security protections, and conduct cross-site scripting attacks.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ise-7Q4TNYUx for more information.

    CVEs related to QID 317276

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ise-7Q4TNYUx URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-7Q4TNYUx