Wednesday, October 3, 2018

Multiple Vulnerabilities in Cisco Identity Services Engine

Two vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit the other. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other.

Details about the vulnerabilities are as follows.

Cisco Identity Services Engine File Upload Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to a web-accessible folder on an affected system and perform arbitrary code execution.

The vulnerability is due to insecure restrictions when files are uploaded to the web-based management interface. An attacker who has valid administrator credentials on the system could exploit this vulnerability by uploading code to be executed on the underlying operating system. A successful exploit could allow the attacker to perform arbitrary code execution in the context of the web server, which runs with non-root privileges.

The CVE ID for this vulnerability is: CVE-2018-15424

The Security Impact Rating (SIR) for this vulnerability is: Medium

Cisco Identity Services Engine Java Deserialization Vulnerability

A vulnerability in Java deserialization in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of the affected device with the privileges of the web server.

The vulnerability is due to insecure deserialization of user-supplied content by the web-based management interface. An attacker who has valid administrator credentials on the device could exploit this vulnerability by sending a crafted serialized Java object. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web server, which runs with non-root privileges.

The CVE ID for this vulnerability is: CVE-2018-15425

The SIR for this vulnerability is: Medium



from Cisco Security Advisory https://ift.tt/2OF4P3n

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.