-0.4 C
New York
Saturday, February 22, 2025

Cisco Patches Crucial ISE Vulnerabilities Enabling Root CmdExec and PrivEsc


Feb 06, 2025Ravie LakshmananUnited States

Cisco Patches Crucial ISE Vulnerabilities Enabling Root CmdExec and PrivEsc

Cisco has launched updates to deal with two important safety flaws Identification Companies Engine (ISE) that would enable distant attackers to execute arbitrary instructions and elevate privileges on inclined gadgets.

The vulnerabilities are listed under –

  • CVE-2025-20124 (CVSS rating: 9.9) – An insecure Java deserialization vulnerability in an API of Cisco ISE that would allow an authenticated, distant attacker to execute arbitrary instructions as the foundation person on an affected system.
  • CVE-2025-20125 (CVSS rating: 9.1) – An authorization bypass vulnerability in an API of Cisco ISE might might allow an authenticated, distant attacker with legitimate read-only credentials to acquire delicate info, change node configurations, and restart the node

An attacker might weaponize both of the issues by sending a crafted serialized Java object or an HTTP request to an unspecified API endpoint, resulting in privilege escalation and code execution.

Cybersecurity

Cisco stated the 2 vulnerabilities should not depending on each other and that there are not any workarounds to mitigate them. They’ve been addressed within the under variations –

  • Cisco ISE software program launch 3.0 (Migrate to a set launch)
  • Cisco ISE software program launch 3.1 (Fastened in 3.1P10)
  • Cisco ISE software program launch 3.2 (Fastened in 3.2P7)
  • Cisco ISE software program launch 3.3 (Fastened in 3.3P4)
  • Cisco ISE software program launch 3.4 (Not susceptible)

Deloitte safety researchers Dan Marin and Sebastian Radulea have been credited with discovering and reporting the vulnerabilities.

Whereas the networking gear main stated it isn’t conscious of any malicious exploitation of the issues, customers are suggested to maintain their methods up-to-date for optimum safety.

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we publish.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles