8.8
CVE-2023-20272
- EPSS 0.89%
- Veröffentlicht 21.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 07:41:02
- Erkennungen
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading a malicious file to the web interface. A successful exploit could allow the attacker to replace files and gain access to sensitive server-side information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version 3.0.0 Update -
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.1 Update -
Cisco ≫ Identity Services Engine Version 3.1 Update patch1
Cisco ≫ Identity Services Engine Version 3.1 Update patch2
Cisco ≫ Identity Services Engine Version 3.1 Update patch3
Cisco ≫ Identity Services Engine Version 3.1 Update patch4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.546 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| Cisco PSIRT | 6.7 | 1.2 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
|
CWE-424 Improper Protection of Alternate Path
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-j-KxpNynR