Privilege Escalation Vulnerability in Cisco Identity Services Engine
CVE-2023-20194
Summary
A vulnerability exists in the ERS API of Cisco's Identity Services Engine that may allow an authenticated remote attacker to read arbitrary files on the system's operating environment. This issue arises from inadequate privilege management in the API, permitting attackers with valid Administrator access to craft specific requests that could escalate privileges. This exploit, if successful, can lead to unauthorized access to sensitive information stored within the device's underlying operating system. The ERS API is not active by default, and administrators can check its status through the Admin GUI by navigating to Administration > Settings > API Settings > API Service Settings.
Affected Version(s)
Cisco Identity Services Engine Software 2.6.0
Cisco Identity Services Engine Software 2.6.0 p1
Cisco Identity Services Engine Software 2.6.0 p2
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved