Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +1 more
- >= 3.3, < 3.4
- 3.4
This vulnerability is being actively exploited in the wild.
A vulnerability exists in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) versions 3.3 and later. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system with root privileges. The issue arises from insufficient validation of user-supplied input, enabling attackers to exploit the vulnerability by sending crafted API requests.
Exploitation of this vulnerability could lead to unauthorized execution of code with root privileges on the affected system.
Cisco has released patches for this vulnerability. Users can upgrade to Cisco ISE or ISE-PIC Release 3.3 Patch 6 or Release 3.4 Patch 2. Instructions for upgrading can be found on the Cisco Identity Services Engine support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.