Логотип exploitDog
bind:CVE-2022-20962
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-20962

Количество 3

Количество 3

nvd логотип

CVE-2022-20962

больше 3 лет назад

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-6f25-35p5-r2r2

больше 3 лет назад

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-06810

больше 3 лет назад

Уязвимость функции управления локальными дисками платформы управления политиками соединений Cisco Identity Services Engine (ISE), позволяющая нарушителю загружать файлы в произвольные места в системе

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-20962

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

CVSS3: 3.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-6f25-35p5-r2r2

A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-06810

Уязвимость функции управления локальными дисками платформы управления политиками соединений Cisco Identity Services Engine (ISE), позволяющая нарушителю загружать файлы в произвольные места в системе

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу