Vulnslist

find the latest Cisco vulnerabilities

CVE-2023-20077

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to download arbitrary files from the underlying filesystem of the affected device.

SeverityMEDIUM
CVSS4.9
CWECWE-37
KEV
Published
Modified

Related Products

Product Advisory
Cisco RV Series Routers cisco-sa-ise-file-dwnld-Srcdnkd2
Cisco Nexus Dashboard cisco-sa-ise-file-dwnld-Srcdnkd2
Cisco Identity Services Engine Software cisco-sa-ise-file-dwnld-Srcdnkd2