PT-2021-5118 · Cisco · Cisco Identity Services Engine

Alexander Polce Leary

·

Published

2021-10-06

·

Updated

2023-06-26

·

CVE-2021-1594

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (affected versions not specified)
Description The issue is related to insufficient input validation for specific API endpoints in the REST API of Cisco Identity Services Engine. This could allow a remote attacker to perform a command injection attack and elevate privileges to root. An attacker in a man-in-the-middle position could exploit this by intercepting and modifying specific internode communications from one ISE persona to another. A successful exploit could allow the attacker to run arbitrary commands with root privileges on the underlying operating system. To exploit this, the attacker would need to decrypt HTTPS traffic between two ISE personas located on separate nodes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Command Injection

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2021-05911
CVE-2021-1594

Affected Products

Cisco Identity Services Engine