cisco-sa-ise-multivuls-FTW9AOXF: Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands and elevate privileges on an affected device. Note: To exploit these vulnerabilities, an attacker must have valid ISE administrative credentials. These vulnerabilities can be exploited using any valid administrative account, including read-only administrative accounts. For more information about these vulnerabilities, see the Details section of this advisory.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ise-multivuls-FTW9AOXF?
The severity of cisco-sa-ise-multivuls-FTW9AOXF is classified as high due to the potential for arbitrary command execution and privilege escalation.
How do I fix cisco-sa-ise-multivuls-FTW9AOXF?
To fix cisco-sa-ise-multivuls-FTW9AOXF, update the Cisco Identity Services Engine to the latest version released by Cisco.
What types of vulnerabilities are addressed in cisco-sa-ise-multivuls-FTW9AOXF?
cisco-sa-ise-multivuls-FTW9AOXF addresses multiple vulnerabilities that enable remote attackers to execute arbitrary commands and elevate privileges.
Who is affected by cisco-sa-ise-multivuls-FTW9AOXF?
Any organization using Cisco Identity Services Engine is potentially affected by cisco-sa-ise-multivuls-FTW9AOXF.
What is required to exploit cisco-sa-ise-multivuls-FTW9AOXF?
An attacker must have valid read-only administrative credentials to exploit cisco-sa-ise-multivuls-FTW9AOXF.