QID 317319
Date Published: 2023-04-10
QID 317319: Cisco Identity Services Engine (ISE) Command Injection Vulnerability (cisco-sa-adeos-MLAyEcvk)
A vulnerability in the restricted shell of Cisco ISE could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.
Affected Versions:
from 3.2 prior to 3.2p1
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of the affected device.
Solution
Customers are advised to refer to cisco-sa-adeos-MLAyEcvk for more information.
Vendor References
- cisco-sa-adeos-MLAyEcvk -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk
CVEs related to QID 317319
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk |
|