CVE-2022-20964: OS Command Injection
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management interface. An attacker could exploit this vulnerability by manipulating requests to the web-based management interface to contain operating system commands. A successful exploit could allow the attacker to execute arbitrary operating system commands on the underlying operating system with the privileges of the web services user. Cisco has not yet released software updates that address this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cisco Identity Services Engine vulnerability?
The vulnerability ID for this Cisco Identity Services Engine vulnerability is CVE-2022-20964.
What is the severity of CVE-2022-20964?
The severity of CVE-2022-20964 is high with a severity value of 8.8.
How does this vulnerability affect Cisco Identity Services Engine?
This vulnerability affects Cisco Identity Services Engine versions up to 2.6.0.
How can an attacker exploit this vulnerability?
An authenticated, remote attacker can exploit this vulnerability by injecting arbitrary commands on the underlying operating system.
How can I fix CVE-2022-20964?
To fix CVE-2022-20964, update Cisco Identity Services Engine to version 2.6.0-patch13 or later.