PT-2023-2801 · Cisco · Cisco Identity Services Engine

Arthur Vidineyev

·

Published

2023-05-17

·

Updated

2023-05-26

·

CVE-2023-20167

CVSS v2.0

6.1

Medium

VectorAV:N/AC:L/Au:M/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified)
Description The issue is related to deficiencies in directory path checking, allowing an attacker to perform path traversal attacks on the underlying operating system. This could enable an attacker to either elevate privileges to root or read arbitrary files. To exploit this, an attacker must have valid Administrator credentials on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02719
CVE-2023-20167

Affected Products

Cisco Identity Services Engine