Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9cx-6464-94g4

Опубликовано: 16 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

EPSS

Процентиль: 37%
0.00158
Низкий

10 Critical

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 10
nvd
20 дней назад

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS3: 10
fstec
около 1 месяца назад

Уязвимость прикладного программного интерфейса платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код с root-привилегиями

EPSS

Процентиль: 37%
0.00158
Низкий

10 Critical

CVSS3

Дефекты

CWE-74