Command injection in Cisco Identity Services Engine (ISE) - CVE-2018-15425
Published: October 9, 2018
Cisco Identity Services Engine (ISE)
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the target system.
The vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE) due to command injection. A remote unauthenticated attacker can inject and execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.