Overview
Cisco Identity Services Engine contains an input validation vulnerability (CWE-20).
Description
CWE-20: Improper Input Validation Cisco Identity Services Engine (ISE) contains an input validation vulnerability. The ISE device contains a TCP Dump option for analyzing traffic on the device. By using a proxy to modify the HTTP request, a remote authenticated attacker can encode commands into the vulnerable format parameter which could allow them to run arbitrary code on the affected system with the privilege of the root user. |
Impact
A remote authenticated attacker may be able to execute arbitrary code as root on the device. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 7.4 | E:F/RL:OF/RC:C |
Environmental | 1.9 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Stephen Hosom for reporting this vulnerability. Cisco also credits Jan Kadijk from Warpnet for first directly reporting this vulnerability.
This document was written by Adam Rauf.
Other Information
CVE IDs: | CVE-2013-5530 |
Date Public: | 2013-10-23 |
Date First Published: | 2013-10-28 |
Date Last Updated: | 2013-11-12 15:03 UTC |
Document Revision: | 43 |