QID 317331
Date Published: 2023-06-05
QID 317331: Cisco Identity Services Engine (ISE) Arbitrary File Download Vulnerabilities (cisco-sa-ise-file-dwnld-Srcdnkd2) (CVE-2023-20087)
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device.
Affected Versions:
from 3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.
Solution
Customers are advised to refer to cisco-sa-ise-file-dwnld-Srcdnkd2 for more information.
Vendor References
- cisco-sa-ise-file-dwnld-Srcdnkd2 -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-dwnld-Srcdnkd2
CVEs related to QID 317331
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-file-dwnld-Srcdnkd2 |
|