CERT-In Advisory
CIAD-2013-0081
Multiple Vulnerabilities in Cisco Identity Services Engine
Original Issue Date: November 04, 2013
Severity Rating: High
Systems Affected
- Cisco Identity Service Engine Software prior to 1.1.1
Overview
Multiple vulnerabilities have been reported in Cisco Identity Service Engine (ISE) Software which could allow a remote attacker to download a full product support bundle and execute arbitrary commands on underlying operating system.
Description
1. Cisco ISE Authenticated Arbitrary Command Execution Vulnerability
(
CVE-2013-5530
)
This vulnerability is in the web framework of Cisco Identity Services Engine (ISE) and due to insufficient input validation. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary commands and execute the affected function. Successful exploitation of this vulnerability could allow a remote attacker to run arbitrary commands on the affected system with the privilege of the root user.
2. Cisco ISE Support Information Download Authentication Bypass Vulnerability
(
CVE-2013-5531
)
This vulnerability is in the implementation of the authentication code that is used to validate requests to download a product support bundle and due to an error in the logic that is used to validate support bundle access requests. An unauthenticated remote attacker could exploit this vulnerability by sending a crafted request to the vulnerable system. Successful exploitation of this vulnerability could allow a remote attacker to obtain a full copy of the product configuration or other sensitive information including administrative credentials.
Solution
Apply appropriate updates as mentioned in CISCO advisory:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-ise
Vendor Information
CISCO
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-ise
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=31294
http://tools.cisco.com/security/center/viewAlert.x?alertId=31295
Security Focus
http://www.securityfocus.com/archive/1/529391
CVE Name
CVE-2013-5530
CVE-2013-5531
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|