Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-00377

Опубликовано: 07 янв. 2026
Источник: fstec
CVSS3: 4.9
CVSS2: 6.8
EPSS Низкий

Описание

Уязвимость платформы управления политиками соединений Cisco Identity Services Engine (ISE) и Cisco ISE Passive Identity Connector (ISE-PIC) связана с неверным ограничением XML-ссылок на внешние объекты. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, загружать произвольные файлы

Вендор

Cisco Systems Inc.

Наименование ПО

Cisco Identity Services Engine
Identity Services Engine Passive Identity Connector (ISE-PIC)

Версия ПО

от 3.2 до 3.2 Patch 8 (Cisco Identity Services Engine)
от 3.3 до 3.3 Patch 8 (Cisco Identity Services Engine)
от 3.2 до 3.2 Patch 8 (Identity Services Engine Passive Identity Connector (ISE-PIC))
от 3.3 до 3.3 Patch 8 (Identity Services Engine Passive Identity Connector (ISE-PIC))
от 3.4 до 3.4 Patch 4 (Cisco Identity Services Engine)
от 3.4 до 3.4 Patch 4 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.2 включительно (Cisco Identity Services Engine)
до 3.2 включительно (Identity Services Engine Passive Identity Connector (ISE-PIC))

Тип ПО

ПО сетевого программно-аппаратного средства
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,8)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,9)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-jWSbSDKt

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 12%
0.0004
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 месяца назад

A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.  This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials.

CVSS3: 4.9
github
около 1 месяца назад

A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information.  This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system that could include sensitive data that should otherwise be inaccessible even to administrators. To exploit this vulnerability, the attacker must have valid administrative credentials.

EPSS

Процентиль: 12%
0.0004
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2