QID 317332
Date Published: 2023-06-05
QID 317332: Cisco Identity Services Engine (ISE) Multiple Vulnerabilities (cisco-sa-ise-file-delete-read-PK5ghDDd)
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device.
CVE-2023-20171 : A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to delete arbitrary files on an affected device.
CVE-2023-20106: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.
CVE-2023-20172: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid Administrator-level privileges on the affected device.
Note: These vulnerabilities can be exploited only by valid and authorized users of the Cisco ISE system. As a best practice, customers can restrict console access and admin web access. To configure the access restrictions, choose Administration > System > Admin Access > Settings > Access > IP Access.
Affected Versions:
from 3.1 prior to 3.1P6
from 3.2 prior to 3.2P2
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to delete arbitrary files on an affected device
Customers are advised to refer to cisco-sa-ise-file-delete-read-PK5ghDDd for more information.
- cisco-sa-ise-file-delete-read-PK5ghDDd -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-delete-read-PK5ghDDd
CVEs related to QID 317332
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-file-delete-read-PK5ghDDd |
|