Back to list

Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities — CISCO-SA-ISE-RCE-TRAVERSAL-8BYNDVRZ

Cisco · Cisco · CISCO-SA-ISE-RCE-TRAVERSAL-8BYNDVRZ

ID
CISCO-SA-ISE-RCE-TRAVERSAL-8BYNDVRZ
Date
Activity
Source
Cisco
Vendor
Cisco
Threat
critical

Summary

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to achieve remote code execution or conduct path traversal attacks on an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the  Details…

Product

Cisco Identity Services Engine Remote Code Execution and Path Traversal

What to do

General, cautious steps (verify details in the official source):

  • Prioritize patching or mitigation immediately (treat as actively risky).
  • Identify affected product versions in your inventory and verify whether you are impacted.
  • Apply vendor patches/updates or recommended mitigations as soon as available.
  • Read the official advisory for exact affected versions and remediation steps.

Official advisory

Related advisories