PT-2018-8718 · Cisco · Cisco Identity Services Engine

Publicado

2018-04-19

·

Atualizado

2019-10-09

·

CVE-2018-0275

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cisco Identity Services Engine (ISE) versions prior to 2.2.0.470
Description: A vulnerability in the support tunnel feature could allow an authenticated, local attacker to access the device's shell due to improper configuration. An attacker could exploit this by tricking the device into unlocking the support user account, accessing the tunnel password and device serial number, and then running any system command with root access.
Recommendations: For versions prior to 2.2.0.470, update to version 2.2.0.470 or later to resolve the issue. As a temporary workaround, consider restricting access to the support tunnel feature until a patch is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0275

Produtos afetados

Cisco Identity Services Engine