A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management functions.
This vulnerability is due to lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to upload files to a location that should be restricted. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Identity_services_engine | Cisco | * | 3.1 (excluding) |
Identity_services_engine | Cisco | 3.1.0 (including) | 3.1.0 (including) |
Identity_services_engine | Cisco | 3.1.0-patch1 (including) | 3.1.0-patch1 (including) |
Identity_services_engine | Cisco | 3.1.0-patch2 (including) | 3.1.0-patch2 (including) |
Identity_services_engine | Cisco | 3.1.0-patch3 (including) | 3.1.0-patch3 (including) |
Identity_services_engine | Cisco | 3.1.0-patch4 (including) | 3.1.0-patch4 (including) |
Identity_services_engine | Cisco | 3.1.0-patch5 (including) | 3.1.0-patch5 (including) |
Identity_services_engine | Cisco | 3.1.0-patch6 (including) | 3.1.0-patch6 (including) |
Identity_services_engine | Cisco | 3.1.0-patch7 (including) | 3.1.0-patch7 (including) |
Identity_services_engine | Cisco | 3.1.0-patch8 (including) | 3.1.0-patch8 (including) |
Identity_services_engine | Cisco | 3.1.0-patch9 (including) | 3.1.0-patch9 (including) |
Identity_services_engine | Cisco | 3.2.0 (including) | 3.2.0 (including) |
Identity_services_engine | Cisco | 3.2.0-patch1 (including) | 3.2.0-patch1 (including) |
Identity_services_engine | Cisco | 3.2.0-patch2 (including) | 3.2.0-patch2 (including) |
Identity_services_engine | Cisco | 3.2.0-patch3 (including) | 3.2.0-patch3 (including) |
Identity_services_engine | Cisco | 3.2.0-patch4 (including) | 3.2.0-patch4 (including) |
Identity_services_engine | Cisco | 3.2.0-patch5 (including) | 3.2.0-patch5 (including) |
Identity_services_engine | Cisco | 3.2.0-patch6 (including) | 3.2.0-patch6 (including) |
Identity_services_engine | Cisco | 3.3.0 (including) | 3.3.0 (including) |
Identity_services_engine | Cisco | 3.3.0-patch1 (including) | 3.3.0-patch1 (including) |
Identity_services_engine | Cisco | 3.3.0-patch2 (including) | 3.3.0-patch2 (including) |
Identity_services_engine | Cisco | 3.3.0-patch3 (including) | 3.3.0-patch3 (including) |