PT-2022-5524 · Cisco · Cisco Identity Services Engine

Davide Virruso

·

Published

2022-11-02

·

Updated

2024-01-25

·

CVE-2022-20956

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified)
Description The issue is related to insufficient access control in the web-based management interface of Cisco Identity Services Engine (ISE), allowing a remote attacker to bypass existing security restrictions and access system files by sending a specially crafted HTTP request. This could enable the attacker to list, download, and delete certain files they should not have access to.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06853
CVE-2022-20956

Affected Products

Cisco Identity Services Engine