First published: Wed Apr 03 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.This vulnerability is due to improper input validation for
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-ise-ssrf-FtSTh5Oz is considered high due to the potential for remote attackers to exploit the SSRF vulnerability.
To fix cisco-sa-ise-ssrf-FtSTh5Oz, apply the security patches released by Cisco for the affected Identity Services Engine version.
cisco-sa-ise-ssrf-FtSTh5Oz allows authenticated attackers to perform SSRF attacks, potentially leading to unauthorized access to internal resources.
Organizations using vulnerable versions of Cisco Identity Services Engine (ISE) are affected by the cisco-sa-ise-ssrf-FtSTh5Oz vulnerability.
After discovering cisco-sa-ise-ssrf-FtSTh5Oz, ensure to immediately update the affected Cisco ISE systems and monitor for any unusual activity.