Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-20077

Опубликовано: 18 мая 2023
Источник: nvd
CVSS3: 4.9
CVSS3: 6.5
EPSS Низкий

Описание

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
Версия до 3.1 (включая)
cpe:2.3:a:cisco:identity_services_engine:3.2:-:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00065
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-37
CWE-22

Связанные уязвимости

CVSS3: 4.9
github
больше 2 лет назад

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.

CVSS3: 4.9
fstec
больше 2 лет назад

Уязвимость веб-интерфейса управления платформы управления политиками соединений Cisco Identity Services Engine (ISE), позволяющая нарушителю загружать произвольные файлы из файловой системы

EPSS

Процентиль: 20%
0.00065
Низкий

4.9 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-37
CWE-22