Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +2 more
- <= 3.0
- >= 3.1, < 3.1P10
- >= 3.2, < 3.2P7
- >= 3.3, < 3.3P4
An authorization bypass vulnerability has been identified in an API of Cisco Identity Services Engine (ISE). This vulnerability allows an authenticated, remote attacker with valid read-only administrative credentials to access sensitive information, modify node configurations, and restart the node. The issue arises from inadequate authorization in a specific API and improper validation of user-supplied data. Exploitation involves sending a crafted HTTP request to the affected API. In single-node deployments, restarting the node can disrupt authentication for new devices during the reload period.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, unauthorized changes to node configurations, and disruption of node operations by causing a restart.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found in the Cisco Identity Services Engine support page. Customers with service contracts should obtain the update through their usual channels. Those without service contracts can contact the Cisco Technical Assistance Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.