PT-2018-8718 · Cisco · Cisco Identity Services Engine
Publicado
2018-04-19
·
Atualizado
2019-10-09
·
CVE-2018-0275
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Cisco Identity Services Engine (ISE) versions prior to 2.2.0.470
Description:
A vulnerability in the support tunnel feature could allow an authenticated, local attacker to access the device's shell due to improper configuration. An attacker could exploit this by tricking the device into unlocking the support user account, accessing the tunnel password and device serial number, and then running any system command with root access.
Recommendations:
For versions prior to 2.2.0.470, update to version 2.2.0.470 or later to resolve the issue. As a temporary workaround, consider restricting access to the support tunnel feature until a patch is applied.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Identity Services Engine