CVE-2022-20956
published 2022-11-04CVE-2022-20956: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.32%
67.5th percentile
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files.
This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to.
Cisco plans to release software updates that address this vulnerability.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx"]
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request to the web-based management interface of Cisco ISE; monitor for anomalous HTTP requests targeting file listing, download, or deletion endpoints on the ISE management interface ↗
- →The vulnerability requires an authenticated session; look for authenticated users performing unauthorized file access operations (list/download/delete) beyond their assigned role permissions on Cisco ISE ↗
- ·Cisco ISE web-based management interface has improper access control; ensure access to the management interface is restricted to trusted networks/hosts and that role-based access controls are correctly enforced ↗
- ·No workarounds are available; patching is the only remediation. Track Cisco Bug IDs CSCwb75965, CSCwc62419, and CSCwc62413 for fix status. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Insufficient Access Control Vulnerability
vendor_cisco·2022-11-02·CVSS 7.1
CVE-2022-20956 [HIGH] CWE-648 Cisco Identity Services Engine Insufficient Access Control Vulnerability
Cisco Identity Services Engine Insufficient Access Control Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files.
This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.clou
Cisco
Cisco Identity Services Engine Insufficient Access Control Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20956 Cisco Identity Services Engine Insufficient Access Control Vulnerability
CVE-2022-20956: Cisco Identity Services Engine Insufficient Access Control Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-648, CWE-648
Bug IDs: CSCwb75965, CSCwc62419, CSCwb75965, CSCwc62413, CSCwc62
GHSA
GHSA-4x6g-xmp8-726r: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass
ghsa_unreviewed·2022-11-04
CVE-2022-20956 [HIGH] CWE-648 GHSA-4x6g-xmp8-726r: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vulnerability. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-acc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-04
Published