QID 317409
Date Published: 2024-01-16
QID 317409: Cisco Identity Services Engine (ISE) Privilege Escalation Vulnerabilities (cisco-sa-ise-priv-esc-KJLp2Aw)
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform privilege escalation attacks to read or modify arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid Administrator-level privileges on the affected device.
Affected Versions:
Prior to version 2.7P10
From 3.0 prior to version 3.0P8
From 3.1 prior to version 3.1P8
From 3.2 prior to version 3.2P3
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using show version command.
Note: This QID does not checks for the ESR and ERS configuration. Hence set as practice.
Successful exploitation could allow an authenticated attacker to perform privilege escalation attacks to read or modify arbitrary files on the underlying operating system.
Customers are advised to refer to cisco-sa-ise-priv-esc-KJLp2Aw for more information.
- cisco-sa-ise-priv-esc-KJLp2Aw -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-priv-esc-KJLp2Aw
CVEs related to QID 317409
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-priv-esc-KJLp2Aw |
|