A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.
This vulnerability is due to a lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to conduct administrative functions beyond their intended access level. To exploit this vulnerability, an attacker would need Read-Only Administrator credentials.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Identity_services_engine | Cisco | 3.0.0 (including) | 3.0.0 (including) |
Identity_services_engine | Cisco | 3.0.0-patch1 (including) | 3.0.0-patch1 (including) |
Identity_services_engine | Cisco | 3.0.0-patch2 (including) | 3.0.0-patch2 (including) |
Identity_services_engine | Cisco | 3.0.0-patch3 (including) | 3.0.0-patch3 (including) |
Identity_services_engine | Cisco | 3.0.0-patch4 (including) | 3.0.0-patch4 (including) |
Identity_services_engine | Cisco | 3.0.0-patch5 (including) | 3.0.0-patch5 (including) |
Identity_services_engine | Cisco | 3.0.0-patch6 (including) | 3.0.0-patch6 (including) |
Identity_services_engine | Cisco | 3.0.0-patch7 (including) | 3.0.0-patch7 (including) |
Identity_services_engine | Cisco | 3.0.0-patch8 (including) | 3.0.0-patch8 (including) |
Identity_services_engine | Cisco | 3.1.0 (including) | 3.1.0 (including) |
Identity_services_engine | Cisco | 3.1.0-patch1 (including) | 3.1.0-patch1 (including) |
Identity_services_engine | Cisco | 3.1.0-patch2 (including) | 3.1.0-patch2 (including) |
Identity_services_engine | Cisco | 3.1.0-patch3 (including) | 3.1.0-patch3 (including) |
Identity_services_engine | Cisco | 3.1.0-patch4 (including) | 3.1.0-patch4 (including) |
Identity_services_engine | Cisco | 3.1.0-patch5 (including) | 3.1.0-patch5 (including) |
Identity_services_engine | Cisco | 3.1.0-patch6 (including) | 3.1.0-patch6 (including) |
Identity_services_engine | Cisco | 3.1.0-patch7 (including) | 3.1.0-patch7 (including) |
Identity_services_engine | Cisco | 3.1.0-patch8 (including) | 3.1.0-patch8 (including) |
Identity_services_engine | Cisco | 3.1.0-patch9 (including) | 3.1.0-patch9 (including) |
Identity_services_engine | Cisco | 3.2.0 (including) | 3.2.0 (including) |
Identity_services_engine | Cisco | 3.2.0-patch1 (including) | 3.2.0-patch1 (including) |
Identity_services_engine | Cisco | 3.2.0-patch2 (including) | 3.2.0-patch2 (including) |
Identity_services_engine | Cisco | 3.2.0-patch3 (including) | 3.2.0-patch3 (including) |
Identity_services_engine | Cisco | 3.2.0-patch4 (including) | 3.2.0-patch4 (including) |
Identity_services_engine | Cisco | 3.2.0-patch5 (including) | 3.2.0-patch5 (including) |
Identity_services_engine | Cisco | 3.2.0-patch6 (including) | 3.2.0-patch6 (including) |
Identity_services_engine | Cisco | 3.3.0 (including) | 3.3.0 (including) |
Identity_services_engine | Cisco | 3.3.0-patch1 (including) | 3.3.0-patch1 (including) |
Identity_services_engine | Cisco | 3.3.0-patch2 (including) | 3.3.0-patch2 (including) |