Cisco Identity Services Engine Command Injection Vulnerabilities

Chronological Source Flow
Back

AI Fusion Summary

Cisco has identified multiple vulnerabilities across Cisco Identity Services Engine (ISE), ISE Passive Identity Connector (ISE-PIC), and Cisco ThousandEyes Virtual Appliance. These flaws include command injection, SQL injection, and HQL injection, potentially allowing authenticated remote attackers with administrative credentials to execute arbitrary root commands or manipulate unauthorized database data. These issues stem from improper input validation. Cisco has released software updates to address these vulnerabilities, though no workarounds are available for the affected systems.
Community Comments
Loading updates...
0