CVE Database
/

CVE-2018-0214

Back to search

CVE-2018-0214

Published: Mar 8, 2018

Modified: Dec 2, 2024

PUBLISHED

Description

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input validation of CLI command user input. An attacker could exploit this vulnerability by authenticating to the targeted device and issuing a CLI command with crafted user input. A successful exploit could allow the attacker to execute arbitrary commands on the affected system that should be restricted. The attacker would need to have valid user credentials for the device. Cisco Bug IDs: CSCvf49844.

VendorProductVersions

n/a

Cisco Identity Services Engine

affected
Cisco Identity Services Engine

Weaknesses (CWE)

References

103331
vdb-entry
x_refsource_BID
1040471
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now