PT-2013-5611 · Cisco · Cisco Identity Services Engine

Jan Kadijk

+1

·

Published

2013-10-25

·

Updated

2016-09-21

·

CVE-2013-5530

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) versions 1.0 through 1.1.0 before 1.1.0.665-5 Cisco Identity Services Engine (ISE) version 1.1.1 before 1.1.1.268-7 Cisco Identity Services Engine (ISE) version 1.1.2 before 1.1.2.145-10 Cisco Identity Services Engine (ISE) version 1.1.3 before 1.1.3.124-7 Cisco Identity Services Engine (ISE) version 1.1.4 before 1.1.4.218-7 Cisco Identity Services Engine (ISE) version 1.2 before 1.2.0.899-2
Description The web framework in Cisco Identity Services Engine (ISE) allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443.
Recommendations For version 1.0, update to a version after 1.1.0.665-5. For version 1.1.0, update to 1.1.0.665-5 or later. For version 1.1.1, update to 1.1.1.268-7 or later. For version 1.1.2, update to 1.1.2.145-10 or later. For version 1.1.3, update to 1.1.3.124-7 or later. For version 1.1.4, update to 1.1.4.218-7 or later. For version 1.2, update to 1.2.0.899-2 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5530

Affected Products

Cisco Identity Services Engine