SB2018100308 - Command execution in Cisco Identity Services Engine
Published: October 3, 2018 Updated: October 9, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Command injection (CVE-ID: CVE-2018-15424)
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
2) Command injection (CVE-ID: CVE-2018-15425)
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
Remediation
Install update from vendor's website.