PT-2013-5611 · Cisco · Cisco Identity Services Engine
Jan Kadijk
+1
·
Published
2013-10-25
·
Updated
2016-09-21
·
CVE-2013-5530
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (ISE) versions 1.0 through 1.1.0 before 1.1.0.665-5
Cisco Identity Services Engine (ISE) version 1.1.1 before 1.1.1.268-7
Cisco Identity Services Engine (ISE) version 1.1.2 before 1.1.2.145-10
Cisco Identity Services Engine (ISE) version 1.1.3 before 1.1.3.124-7
Cisco Identity Services Engine (ISE) version 1.1.4 before 1.1.4.218-7
Cisco Identity Services Engine (ISE) version 1.2 before 1.2.0.899-2
Description
The web framework in Cisco Identity Services Engine (ISE) allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443.
Recommendations
For version 1.0, update to a version after 1.1.0.665-5.
For version 1.1.0, update to 1.1.0.665-5 or later.
For version 1.1.1, update to 1.1.1.268-7 or later.
For version 1.1.2, update to 1.1.2.145-10 or later.
For version 1.1.3, update to 1.1.3.124-7 or later.
For version 1.1.4, update to 1.1.4.218-7 or later.
For version 1.2, update to 1.2.0.899-2 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Identity Services Engine