QID 317327
Date Published: 2023-05-25
QID 317327: Cisco Identity Services Engine (ISE) Path Traversal Vulnerability (CVE-2023-20167) (cisco-sa-ise-traversal-ZTUgMYhu)
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files.
Affected Versions:
2.7 and earlier
3.0
3.1 prior to 3.1P8
3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to read arbitrary files of specific types from the underlying operating system.
Solution
Customers are advised to refer to cisco-sa-ise-traversal-ZTUgMYhu for more information.
Vendor References
- cisco-sa-ise-traversal-ZTUgMYhu -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-ZTUgMYhu
CVEs related to QID 317327
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-traversal-ZTUgMYhu |
|