PT-2022-5727 · Cisco · Cisco Identity Services Engine

Davide Virruso

·

Published

2022-11-16

·

Updated

2024-01-25

·

CVE-2022-20964

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (affected versions not specified)
Description The issue is related to the improper validation of user input within requests as part of the web-based management interface, allowing an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This could enable the attacker to execute arbitrary operating system commands with the privileges of the web services user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-07125
CVE-2022-20964

Affected Products

Cisco Identity Services Engine