First published: Thu May 18 2023(Updated: )
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine | =3.2 | |
Cisco Identity Services Engine | =3.2-patch1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-20166 is a vulnerability in Cisco Identity Services Engine (ISE) that could allow an authenticated attacker to perform path traversal attacks on the underlying operating system.
CVE-2023-20166 has a severity rating of medium (6.7).
CVE-2023-20166 affects Cisco Identity Services Engine version 3.2 and 3.2-patch1.
To exploit CVE-2023-20166, an attacker must have valid Administrator credentials and can perform path traversal attacks on the underlying operating system.
More information about CVE-2023-20166 can be found in the Cisco Security Advisory: [Cisco Security Advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-ZTUgMYhu).