QID 317326
Date Published: 2023-05-24
QID 317326: Cisco Identity Services Engine (ISE) Path Traversal Vulnerability (CVE-2023-20166) (cisco-sa-ise-traversal-ZTUgMYhu)
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files.
Affected Versions:
3.2 Prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of the affected device.
Solution
Customers are advised to refer to cisco-sa-ise-traversal-ZTUgMYhu for more information.
Vendor References
- cisco-sa-ise-traversal-ZTUgMYhu -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-ZTUgMYhu
CVEs related to QID 317326
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-traversal-ZTUgMYhu |
|