Cisco Security Update 14 December 2022

Cisco has released a security update to fix a vulnerability in Cisco Identity Services Engine (ISE).

The addressed vulnerability could allow the remote authenticated attacker to traverse directories on the system; The attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) to read or delete arbitrary files on the system.

Cisco Identity Services Engine (ISE) directory traversal (CVE-2022-20822):

• CVSS: 7.1

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Obtain information

Vulnerabilities
  • CVE-2022-20822
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Cisco Security Advisory

References