PT-2023-2801 · Cisco · Cisco Identity Services Engine

Arthur Vidineyev

·

Publicado

2023-05-17

·

Atualizado

2023-05-26

·

CVE-2023-20167

CVSS v2.0

6.1

Média

VetorAV:N/AC:L/Au:M/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified)
Description The issue is related to deficiencies in directory path checking, allowing an attacker to perform path traversal attacks on the underlying operating system. This could enable an attacker to either elevate privileges to root or read arbitrary files. To exploit this, an attacker must have valid Administrator credentials on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02719
CVE-2023-20167

Produtos afetados

Cisco Identity Services Engine