A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.
The vulnerability results from insufficient validation of user-supplied data (CWE-77 — command injection). An attacker possessing valid administrative credentials can send a specially crafted HTTP request to the vulnerable device. Following a successful attack, the attacker gains access to the operating system at user level, then performs privilege escalation to root privileges. In environments with a single ISE node, successful exploitation can cause node unavailability and prevent new endpoints from authenticating on the network until service is restored.
An attacker can gain full control over the device's operating system (root privileges), enabling data reading and modification, malicious software installation, and triggering a DoS state that prevents network access for newly authenticating endpoints.
Apply patches available from the vendor according to references — detailed versions of fixed releases are contained in the official Cisco Security Advisory bulletin at: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ. Additionally, it is recommended to restrict administrative access to the ISE management interface exclusively to trusted networks/hosts.
Cisco Identity Services Engine (ISE) and Cisco ISE-PIC — versions indicated in vendor references (advisory cisco-sa-ise-rce-traversal-8bYndVrZ).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCisco Identity Services Engine
APPCisco3.1.03.2.03.3.03.4.03.5.0< 3.1.0Cisco Identity Services Engine Passive Identity Connector
APPCisco3.1.03.2.03.3.03.4.03.5.0< 3.1.0
Related vulnerabilities
Nieuwierzytelniony RCE jako root w Cisco ISE i ISE-PIC poprzez API
Cisco ISE / ISE-PIC — nieuwierzytelniony RCE przez API jako root
RCE i privilege escalation w Cisco ISE i ISE-PIC poprzez path traversal
RCE z eskalacją do root w Cisco Identity Services Engine (ISE)
RCE w Cisco ISE — eskalacja uprawnień do root przez HTTP