(I)IoT Security News
Critical vulnerabiliities, Vulnerabilities

Cisco Releases Security Updates for Identity Services Engine

Cisco has released security updates for vulnerabilities affecting Cisco Identity Services Engine (ISE). A remote attacker could exploit some of these vulnerabilities to bypass authorization and access system files. 

CISA encourages users and administrators to review the following advisories and apply the necessary updates:

Cisco Identity Services Engine Insufficient Access Control Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files.

This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to.

Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected Products

Fixed Software

Exploitation and Public Announcements

URL

Source:

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx

Related posts

Siemens KTK, SIDOOR, SIMATIC, and SINAMICS (Update A)

(I) IoT
4 years ago

Cisco Expressway Series Cross-Site Request Forgery Vulnerabilities

(I) IoT
3 months ago

Siemens TIM 1531 IRC Modules

(I) IoT
5 years ago
Exit mobile version