Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +1 more
- < 3.1
- < 3.2
- < 3.3
- < 3.4
- < 3.5
- 3.1
- 3.2
- 3.3
- 3.4
- 3.5
A remote code execution vulnerability has been identified in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows an authenticated attacker with administrative credentials to execute arbitrary commands on the underlying operating system of the affected device. The issue arises from insufficient validation of user-supplied input, enabling exploitation through crafted HTTP requests. In single-node ISE deployments, successful exploitation could lead to a denial-of-service condition, causing the ISE node to become unavailable and disrupting network access for unauthenticated endpoints.
Exploitation of this vulnerability could result in unauthorized remote code execution on the affected device, with potential escalation of privileges to root. In single-node ISE deployments, this exploitation could cause the ISE node to become unavailable, creating a denial-of-service condition that prevents unauthenticated endpoints from accessing the network until the node is restored.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Identity Services Engine support page. For versions earlier than 3.1, users are advised to migrate to a fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.