4.9
CVE-2023-20173
- EPSS 0.77%
- Veröffentlicht 18.05.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 07:40:44
- Erkennungen
Cisco Identity Services Engine XML External Entity Injection Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version < 3.0.0
Cisco ≫ Identity Services Engine Version 3.0.0 Update -
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.1 Update -
Cisco ≫ Identity Services Engine Version 3.1 Update patch1
Cisco ≫ Identity Services Engine Version 3.1 Update patch3
Cisco ≫ Identity Services Engine Version 3.1 Update patch4
Cisco ≫ Identity Services Engine Version 3.1 Update patch5
Cisco ≫ Identity Services Engine Version 3.1 Update patch6
Cisco ≫ Identity Services Engine Version 3.2 Update -
Cisco ≫ Identity Services Engine Version 3.2 Update patch1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.506 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| Cisco PSIRT | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-696OZTCm