QID 317325
Date Published: 2023-05-25
QID 317325: Cisco Identity Services Engine (ISE) Extensible Markup Language (XML) External Entity Injection Vulnerabilities (cisco-sa-ise-xxe-inj-696OZTCm)
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device.
Affected Versions:
2.7 and earlier
3.0 prior to 3.0P8
3.1 prior to 3.1P7
3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of confidential information.
Solution
Customers are advised to refer to cisco-sa-ise-injection-2XbOg9Dg for more information.
Vendor References
- cisco-sa-ise-xxe-inj-696OZTCm -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-696OZTCm
CVEs related to QID 317325
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-xxe-inj-696OZTCm |
|