Lucene search

K
ciscoCiscoCISCO-SA-ADEOS-MLAYECVK
HistoryApr 05, 2023 - 4:00 p.m.

Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities

2023-04-0516:00:00
tools.cisco.com
17
cisco
epnm
ise
prime infrastructure
command injection
vulnerabilities
restricted shell
software updates
root privileges
advisory link

0.0004 Low

EPSS

Percentile

5.2%

Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system.

For more information about these vulnerabilities, see the Details [“#details”] section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-adeos-MLAyEcvk”]

Affected configurations

Vulners
Node
ciscoidentity_services_engine_softwareMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoevolved_programmable_network_managerMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoevolved_programmable_network_managerMatchany

0.0004 Low

EPSS

Percentile

5.2%

Related for CISCO-SA-ADEOS-MLAYECVK