cbcvebase.
CVE-2022-20962
published 2022-11-04

CVE-2022-20962: A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.95%
57.2th percentile
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscoidentity_services_engine
ciscoidentity_services_engine_path

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted HTTP requests containing absolute path sequences targeting the Localdisk Management feature of Cisco ISE, which may indicate a path traversal exploitation attempt.
  • Monitor for unauthorized file uploads to arbitrary locations within the Cisco ISE file system, particularly outside expected directories, as this is the primary impact of successful exploitation.
  • Alert on unexpected OS-level command execution with system privileges on Cisco ISE appliances, which may follow a successful path traversal file upload.
  • ·Exploitation requires an authenticated session; unauthenticated attackers cannot directly exploit this vulnerability. Ensure monitoring covers authenticated user activity on Cisco ISE.
  • ·There are no workarounds available; patching is the only remediation. Prioritize detection on unpatched Cisco ISE instances (tracked under Bug ID CSCwb75941).
  • ·The vulnerability is classified under CWE-37 (Path Traversal: Absolute Path Sequences), meaning detection rules should specifically focus on absolute path sequences (e.g., leading '/' characters) in HTTP request parameters targeting the Localdisk Management endpoint.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.