CVE-2021-1594
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specific API endpoints. An attacker in a man-in-the-middle position could exploit this vulnerability by intercepting and modifying specific internode communications from one ISE persona to another ISE persona. A successful exploit could allow the attacker to run arbitrary commands with root privileges on the underlying operating system. To exploit this vulnerability, the attacker would need to decrypt HTTPS traffic between two ISE personas that are located on separate nodes.
EPSS 0.15% · 34.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | identity_services_engine | 2.6.0, 2.6\(0.156\), 2.6.0 |
| Cisco | Cisco Identity Services Engine Software | n/a |
Exploit Intelligence
Timeline
- Oct 6, 2021 CVE Published
- Oct 7, 2021 EPSS Score
- Dec 3, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 28, 2022 EPSS Score
- Mar 26, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 22, 2022 EPSS Score
- Jul 19, 2022 EPSS Score
- Sep 13, 2022 EPSS Score
- Nov 9, 2022 EPSS Score
- Jan 5, 2023 EPSS Score
References
- 20211006 Cisco Identity Services Engine Privilege Escalation Vulnerability vendor-advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-dos-fmHdKswk advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multivuln-A4J57F3 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucsi2-command-inject-CGyC8y2R advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-lib-hija-cAFB7x4q advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb220-lldp-multivuls-mVRUtQ8T advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-1594 advisory