QID 317329
Date Published: 2023-05-24
QID 317329: Cisco Identity Services Engine (ISE) Command Injection Vulnerability (cisco-sa-ise-injection-sRQnsEU9) (CVE-2023-20164)
A vulnerability in specific CLI commands in Cisco ISE could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device.
Note: These vulnerabilities can be exploited only by valid and authorized users of the Cisco ISE system. As a best practice, customers can restrict console access and admin web access. To configure the access restrictions, choose Administration > System > Admin Access > Settings > Access > IP Access.
Affected Versions:
from 3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to elevate privileges to root.
Customers are advised to refer to cisco-sa-ise-injection-sRQnsEU9 for more information.
- cisco-sa-ise-injection-sRQnsEU9 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-sRQnsEU9
CVEs related to QID 317329
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-injection-sRQnsEU9 |
|