Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8xq5-r7g5-m3f8

Опубликовано: 06 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.

This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.

This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.

EPSS

Процентиль: 15%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-602

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions. This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость веб-интерфейса управления платформы управления политиками соединений Cisco Identity Services Engine (ISE), позволяющая нарушителю загружать произвольные файлы

EPSS

Процентиль: 15%
0.00047
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-602