First published: Wed Sep 04 2024(Updated: )
A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The cisco-sa-ise-injection-6kn9tSxm vulnerability has a high severity rating due to the potential for command injection and privilege escalation.
To fix cisco-sa-ise-injection-6kn9tSxm, upgrade to the latest version of Cisco Identity Services Engine that addresses this vulnerability.
Only authenticated, local attackers can exploit the cisco-sa-ise-injection-6kn9tSxm vulnerability, as they need access to specific CLI commands.
The cisco-sa-ise-injection-6kn9tSxm vulnerability affects Cisco Identity Services Engine (ISE) software.
The cisco-sa-ise-injection-6kn9tSxm vulnerability can lead to command injection attacks, allowing an attacker to gain root privileges on the underlying operating system.