First published: Thu May 18 2023(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | <=3.1 | |
Cisco Identity Services Engine | =3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-20077.
The severity rating of CVE-2023-20077 is medium (6.5).
An authenticated, remote attacker can exploit CVE-2023-20077 to download arbitrary files from the filesystem of an affected device.
Versions up to (inclusive) 3.1 and version 3.2 of Cisco Identity Services Engine (ISE) are affected by CVE-2023-20077.
Yes, Cisco has provided a security advisory with recommended mitigations for CVE-2023-20077. Please refer to the reference URL for more information.