Command injection in Cisco Identity Services Engine (ISE) - CVE-2018-15424

 

Command injection in Cisco Identity Services Engine (ISE) - CVE-2018-15424

Published: October 3, 2018 / Updated: October 9, 2018


Vulnerability identifier: #VU15212
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15424
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.

The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2018-15424

The vulnerability has been fixed in the versions 2.2(1.901), 2.2(0.910).

Cisco Identity Services Engine (ISE) - addressed in versions 2.2.0.910, 2.2.1.901

External References

Related Security Bulletins