Privilege Escalation Vulnerability in Cisco Identity Services Engine
CVE-2023-20194

4.9MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
7 September 2023

Badges

👾 Exploit Exists

Summary

A vulnerability exists in the ERS API of Cisco's Identity Services Engine that may allow an authenticated remote attacker to read arbitrary files on the system's operating environment. This issue arises from inadequate privilege management in the API, permitting attackers with valid Administrator access to craft specific requests that could escalate privileges. This exploit, if successful, can lead to unauthorized access to sensitive information stored within the device's underlying operating system. The ERS API is not active by default, and administrators can check its status through the Admin GUI by navigating to Administration > Settings > API Settings > API Service Settings.

Affected Version(s)

Cisco Identity Services Engine Software 2.6.0

Cisco Identity Services Engine Software 2.6.0 p1

Cisco Identity Services Engine Software 2.6.0 p2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.