Privilege escalation in Cisco Identity Services Engine (ISE) - CVE-2018-15459
Published: January 24, 2019
Cisco Identity Services Engine (ISE)
Detailed vulnerability description
The vulnerability allows a remote authenticated attacker to gain elevated privileges.
The vulnerability exists due to improper controls on certain pages in the web interface. A remote attacker can authenticate to the device with an administrator account and sending a crafted HTTP request, create additional Admin accounts with different user roles and then use these accounts to perform actions within their scope.