Privilege escalation in Cisco Identity Services Engine (ISE) - CVE-2018-15459

 

Privilege escalation in Cisco Identity Services Engine (ISE) - CVE-2018-15459

Published: January 24, 2019


Vulnerability identifier: #VU17191
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15459
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to gain elevated privileges.

The vulnerability exists due to improper controls on certain pages in the web interface. A remote attacker can authenticate to the device with an administrator account and sending a crafted HTTP request, create additional Admin accounts with different user roles and then use these accounts to perform actions within their scope.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2018-15459

The vulnerability has been addressed in the versions 2.4(0.902), 2.3(0.905), 2.2(1.901), 2.2(0.910).

Cisco Identity Services Engine (ISE) - addressed in versions 2.2.0.910, 2.2.1.901, 2.3.0.905, 2.4.0.902

External References

Related Security Bulletins