Cisco Identity Services Engine Privilege Escalation (cisco-sa-ise-priv-esc-fNZX8hHj)

medium Nessus Plugin ID 149455

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, Cisco Identity Services Engine Software is affected by a Privilege Escalation vulnerability. A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator account on an affected device. The vulnerability is due to incorrect privilege assignment. An attacker could exploit this vulnerability by logging in to the system with a crafted Active Directory account. A successful exploit could allow the attacker to obtain root privileges on an affected device.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvv08885

See Also

http://www.nessus.org/u?e6392a8e

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv08885

Plugin Details

Severity: Medium

ID: 149455

File Name: cisco-sa-ise-priv-esc-fNZX8hHj.nasl

Version: 1.5

Type: local

Family: CISCO

Published: 5/13/2021

Updated: 6/3/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-27122

CVSS v3

Risk Factor: Medium

Base Score: 6.7

Temporal Score: 5.8

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 11/4/2020

Vulnerability Publication Date: 11/4/2020

Reference Information

CVE: CVE-2020-27122

CWE: 266

CISCO-SA: cisco-sa-ise-priv-esc-fNZX8hHj

IAVA: 2020-A-0500-S

CISCO-BUG-ID: CSCvv08885