QID 317403
Date Published: 2023-12-18
QID 317403: Cisco Identity Services Engine (ISE) Remote Code Execution (RCE) Vulnerability (cisco-sa-struts-C2kCMkmT)
An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.
Affected Versions:
Identity Services Engine (ISE) Prior to release 3.1
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
Note: Only the Sponsor and Certificate Provisioning portals are vulnerable.
Successful exploitation could lead to Remote Code Execution.
Solution
Customers are advised to refer to cisco-sa-struts-C2kCMkmT for more information.
Vendor References
- cisco-sa-struts-C2kCMkmT -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-struts-C2kCMkmT
CVEs related to QID 317403
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-struts-C2kCMkmT |
|