Vulnslist

find the latest Cisco vulnerabilities

CVE-2020-27122

A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator account on an affected device. The vulnerability is due to incorrect privilege assignment. An attacker could exploit this vulnerability by logging in to the system with a crafted Active Directory account. A successful exploit could allow the attacker to obtain root privileges on an affected device.

SeverityMEDIUM
CVSS6.7
CWECWE-266
KEV
Published
Modified

Related Products

Product Advisory
Cisco RV Series Routers cisco-sa-ise-priv-esc-fNZX8hHj
Cisco Nexus Dashboard cisco-sa-ise-priv-esc-fNZX8hHj
Cisco Application Centric Infrastructure Virtual Edge cisco-sa-ise-priv-esc-fNZX8hHj
Cisco Identity Services Engine Software cisco-sa-ise-priv-esc-fNZX8hHj