Improper Authorization in Cisco Identity Services Engine (ISE) - CVE-2020-3467
Published: October 8, 2020 / Updated: October 13, 2020
Cisco Identity Services Engine (ISE)
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to improper enforcement of role-based access control (RBAC) within the web-based management interface. A remote authenticated attacker can send a specially crafted HTTP request and modify parts of the configuration.