PT-2017-3407 · Cisco · Cisco Ise Virtual Appliance+2

Publicado

2017-11-01

·

Atualizado

2019-10-09

·

CVE-2017-12261

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) versions 1.4 through 2.1.0 Cisco ISE Express versions 1.4 through 2.1.0 Cisco ISE Virtual Appliance versions 1.4 through 2.1.0
Description A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The issue is due to incomplete input validation of user input for CLI commands issued at the restricted shell. An attacker could exploit this by authenticating to the targeted device and executing commands that could lead to elevated privileges, requiring valid user credentials to the device.
Recommendations For Cisco Identity Services Engine (ISE) versions 1.4 through 2.1.0, consider restricting access to the SSH interface until a patch is available. For Cisco ISE Express versions 1.4 through 2.1.0, restrict the use of CLI commands that could lead to elevated privileges. For Cisco ISE Virtual Appliance versions 1.4 through 2.1.0, limit the execution of arbitrary CLI commands to minimize the risk of exploitation. As a temporary workaround, consider disabling the use of the restricted shell via SSH until a patch is available.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00195
CVE-2017-12261

Produtos afetados

Cisco Ise Express
Cisco Ise Virtual Appliance
Cisco Identity Services Engine