Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-05529

Опубликовано: 15 апр. 2026
Источник: fstec
CVSS3: 4.9
CVSS2: 6.8
EPSS Низкий

Описание

Уязвимость веб-интерфейса платформы управления политиками соединений Cisco Identity Services Engine (ISE) и виртуального устройства сбора данных об аутентификации пользователей Cisco ISE Passive Identity Connector (ISE-PIC) связана с неверным ограничением имени пути к каталогу с ограниченным доступом. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код

Вендор

Cisco Systems Inc.

Наименование ПО

Cisco Identity Services Engine
Identity Services Engine Passive Identity Connector (ISE-PIC)

Версия ПО

до 3.1 включительно (Cisco Identity Services Engine)
до 3.1 включительно (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.1 Patch 11 (Cisco Identity Services Engine)
до 3.2 Patch 10 (Cisco Identity Services Engine)
до 3.3 Patch 11 (Cisco Identity Services Engine)
до 3.4 Patch 6 (Cisco Identity Services Engine)
до 3.5 Patch 3 (Cisco Identity Services Engine)
до 3.1 Patch 11 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.2 Patch 10 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.3 Patch 11 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.4 Patch 6 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.5 Patch 3 (Identity Services Engine Passive Identity Connector (ISE-PIC))

Тип ПО

ПО сетевого программно-аппаратного средства
ПО виртуализации/ПО виртуального программно-аппаратного средства

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,8)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,9)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 93%
0.06919
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 4.9
nvd
4 месяца назад

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.

CVSS3: 4.9
github
4 месяца назад

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.

EPSS

Процентиль: 93%
0.06919
Низкий

4.9 Medium

CVSS3

6.8 Medium

CVSS2