QID 317385
Date Published: 2023-11-06
QID 317385: Cisco Identity Services Engine (ISE) Command Injection Vulnerability (cisco-sa-ise-injection-QeXegrCw) (CVE-2023-20170)
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
Affected Versions:
From 3.2 prior to version 3.2P3
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to elevate privileges to root.
Solution
Customers are advised to refer to cisco-sa-ise-priv-esc-KJLp2Aw for more information.
Vendor References
- cisco-sa-ise-injection-QeXegrCw -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-QeXegrCw
CVEs related to QID 317385
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-injection-QeXegrCw |
|