Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-05636

Опубликовано: 15 апр. 2026
Источник: fstec
CVSS3: 6
CVSS2: 6.2
EPSS Низкий

Описание

Уязвимость интерфейса командной строки платформы управления политиками соединений Cisco Identity Services Engine (ISE) и виртуального устройства сбора данных об аутентификации пользователей Cisco ISE Passive Identity Connector (ISE-PIC) связана с неправильным кодированием или экранированием выходных данных. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии

Вендор

Cisco Systems Inc.

Наименование ПО

Cisco Identity Services Engine
Identity Services Engine Passive Identity Connector (ISE-PIC)

Версия ПО

до 3.3 Patch 11 (Cisco Identity Services Engine)
до 3.4 Patch 6 (Cisco Identity Services Engine)
до 3.5 Patch 3 (Cisco Identity Services Engine)
до 3.3 Patch 11 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.4 Patch 6 (Identity Services Engine Passive Identity Connector (ISE-PIC))
до 3.5 Patch 3 (Identity Services Engine Passive Identity Connector (ISE-PIC))

Тип ПО

ПО сетевого программно-аппаратного средства
ПО виртуализации/ПО виртуального программно-аппаратного средства

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,2)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 6)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 39%
0.00499
Низкий

6 Medium

CVSS3

6.2 Medium

CVSS2

Связанные уязвимости

CVSS3: 6
nvd
4 месяца назад

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit could allow the attacker to elevate their privileges to root on the underlying operating system.

CVSS3: 6
github
4 месяца назад

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit could allow the attacker to elevate their privileges to root on the underlying operating system.

EPSS

Процентиль: 39%
0.00499
Низкий

6 Medium

CVSS3

6.2 Medium

CVSS2