VDB
CVE-2023-20022
CVE-2023-20022
PUBLISHED
In Cisco Identity Services Engine (ISE) existieren mehrere Schwachstellen. Diese sind aufgrund einer unzureichenden Validierung von Befehlen auf der Kommandozeile zurückzuführen. Ein lokaler Angreifer kann diese Privilegien zu erweitern.
EPSS 0.31% · 54.5th percentile
Risk Scores
EPSS Score
0.31%
54.5th percentile
Exploit Intelligence
Timeline
- Feb 1, 2023 CVE Published
- Apr 6, 2023 EPSS Score
- May 14, 2023 EPSS Score
- Jun 21, 2023 EPSS Score
- Jul 29, 2023 EPSS Score
- Sep 5, 2023 EPSS Score
- Oct 13, 2023 EPSS Score
- Nov 20, 2023 EPSS Score
- Dec 28, 2023 EPSS Score
- Feb 3, 2024 EPSS Score
- Mar 12, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2023/wid-sec-w-2023-0253.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0253 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xxe-inj-GecEHY58 advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-os-injection-pxhKsDM advisory