cisco-sa-20171101-ise: Cisco Identity Services Engine Privilege Escalation Vulnerability
Published Nov 1, 2017
·Updated
Credit
This vulnerability was reported to Cisco by an anonymous security researcher.
Affected Software
1 affected componentFixes available
Cisco Identity Services Engine=1.4, <1.4 patch 12 (see note), =1.3, <Affected; migrate to 1.4 patch 12
1.4 patch 12 (see note)Affected; migrate to 1.4 patch 12
Event History
Nov 1, 2017
Advisory Published
via Cisco·04:00 PM
Data Sourced
via Cisco·04:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of cisco-sa-20171101-ise?
The severity of cisco-sa-20171101-ise is high with a CVSS score of 7.8.
2
How do I fix cisco-sa-20171101-ise?
To fix cisco-sa-20171101-ise, apply the appropriate software updates released by Cisco for the Identity Services Engine.
3
What type of vulnerability is cisco-sa-20171101-ise?
cisco-sa-20171101-ise is a privilege escalation vulnerability affecting Cisco Identity Services Engine.
4
What is the impact of cisco-sa-20171101-ise?
The impact of cisco-sa-20171101-ise could allow an authenticated, low-privileged attacker to elevate their privileges.
5
When was cisco-sa-20171101-ise published?
cisco-sa-20171101-ise was published on November 1, 2017.