Cisco Identity Services Engine Authentication Bypass Vulnerability
Cisco patched an unauthenticated API authentication bypass in Identity Services Engine allowing attackers to access the web-based management interface.
A vulnerability in an API of Cisco Identity Services Engine (ISE) stems from insufficient authentication control on an API endpoint. An unauthenticated remote attacker can send a crafted request to bypass authentication and gain unauthorized access to the device via the web-based management interface. Cisco has released software updates and no workarounds are available.
- Unauthenticated remote authentication bypass via crafted API request
- Grants access to the ISE web-based management interface
- No workarounds; software updates are the only fix
- ISE is widely deployed for network access control and identity policy
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following…
This source does not provide full text. Read it at sec.cloudapps.cisco.com.