QID 317328
Date Published: 2023-05-24
QID 317328: Cisco Identity Services Engine (ISE) Command Injection Vulnerability (cisco-sa-ise-injection-sRQnsEU9) (CVE-2023-20163)
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device.
Note: These vulnerabilities can be exploited only by valid and authorized users of the Cisco ISE system. As a best practice, customers can restrict console access and admin web access. To configure the access restrictions, choose Administration > System > Admin Access > Settings > Access > IP Access.
Affected Versions:
prior to 3.0P8
from 3.1 prior to 3.1P7
from 3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to execute arbitrary operating system commands on the underlying operating system with the privileges of the web services user.
Customers are advised to refer to cisco-sa-ise-injection-sRQnsEU9 for more information.
- cisco-sa-ise-injection-sRQnsEU9 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-sRQnsEU9
CVEs related to QID 317328
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-injection-sRQnsEU9 |
|