PT-2021-5118 · Cisco · Cisco Identity Services Engine
Alexander Polce Leary
·
Published
2021-10-06
·
Updated
2023-06-26
·
CVE-2021-1594
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (affected versions not specified)
Description
The issue is related to insufficient input validation for specific API endpoints in the REST API of Cisco Identity Services Engine. This could allow a remote attacker to perform a command injection attack and elevate privileges to root. An attacker in a man-in-the-middle position could exploit this by intercepting and modifying specific internode communications from one ISE persona to another. A successful exploit could allow the attacker to run arbitrary commands with root privileges on the underlying operating system. To exploit this, the attacker would need to decrypt HTTPS traffic between two ISE personas located on separate nodes.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Command Injection
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Identity Services Engine