SB2018100308 - Command execution in Cisco Identity Services Engine



SB2018100308 - Command execution in Cisco Identity Services Engine

Published: October 3, 2018 Updated: October 9, 2018

Security Bulletin ID SB2018100308
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Command injection (CVE-ID: CVE-2018-15424)

The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.

The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.


2) Command injection (CVE-ID: CVE-2018-15425)

The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.

The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.


Remediation

Install update from vendor's website.