Improper access control in Cisco Identity Services Engine (ISE) - CVE-2022-20956

 

Improper access control in Cisco Identity Services Engine (ISE) - CVE-2022-20956

Published: November 2, 2022


Vulnerability identifier: #VU68960
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20956
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the web-based management interface of an affected device. A remote user can bypass implemented security restrictions and gain list, download, and delete certain files that they should not have access to.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2022-20956

Install updates from vendor's website.


External References

Related Security Bulletins