Two vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
The vulnerabilities are not dependent on one another; exploitation of one of the vulnerabilities is not required to exploit the other. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other.
Details about the vulnerabilities are as follows.
Cisco Identity Services Engine File Upload Code Execution Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to a web-accessible folder on an affected system and perform arbitrary code execution.
The vulnerability is due to insecure restrictions when files are uploaded to the web-based management interface. An attacker who has valid administrator credentials on the system could exploit this vulnerability by uploading code to be executed on the underlying operating system. A successful exploit could allow the attacker to perform arbitrary code execution in the context of the web server, which runs with non-root privileges.
The CVE ID for this vulnerability is: CVE-2018-15424
The Security Impact Rating (SIR) for this vulnerability is: Medium
Cisco Identity Services Engine Java Deserialization Vulnerability
A vulnerability in Java deserialization in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of the affected device with the privileges of the web server.
The vulnerability is due to insecure deserialization of user-supplied content by the web-based management interface. An attacker who has valid administrator credentials on the device could exploit this vulnerability by sending a crafted serialized Java object. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web server, which runs with non-root privileges.
The CVE ID for this vulnerability is: CVE-2018-15425
The SIR for this vulnerability is: Medium
from Cisco Security Advisory https://ift.tt/2OF4P3n
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.