Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +1 more
- >= 3.3, < 3.3 Patch 7
- >= 3.4, < 3.4 Patch 2
A vulnerability exists in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability arises from inadequate validation of user-supplied input. An attacker with valid high-privileged credentials could exploit this issue by sending a crafted API request, leading to the execution of commands with root privileges.
Exploitation of this vulnerability allows for authenticated remote code execution on the affected system as the root user.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Identity Services Engine support page. At the time of publication, the first fixed releases for this vulnerability were Cisco ISE version 3.3 Patch 7 and 3.4 Patch 2.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.