EXECUTIVE SUMMARY:
A command injection vulnerability, CVE-2024-20469, found in its Identity Services Engine (ISE) solution, which allows authenticated local attackers to escalate privileges to root on vulnerable systems. This flaw arises from improper input validation in specific CLI commands, enabling attackers with Administrator privileges to inject malicious commands into the underlying operating system. While the vulnerability requires local access and authenticated Administrator credentials, exploit code for this issue is publicly available. Cisco has stated that the flaw does not impact all ISE versions and has released patches for affected versions. No instances of the vulnerability being actively exploited in the wild have been reported. Additionally, other critical vulnerabilities have been addressed, including a backdoor account in the Smart Licensing Utility Windows software and CVE-2024-20295, a privilege escalation flaw in the Integrated Management Controller (IMC). A patch was issued for CVE-2024-20401, a flaw in Security Email Gateway (SEG) appliances that allowed attackers to add rogue root users and crash systems via malicious emails. Furthermore, a critical vulnerability in Smart Software Manager On-Prem (SSM On-Prem) license servers was highlighted, enabling attackers to modify any user’s password, including those of administrators.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A command injection vulnerability, CVE-2024-20469, found in its Identity Services Engine (ISE) solution, which allows authenticated local attackers to escalate privileges to root on vulnerable systems. This flaw arises from improper input validation in specific CLI commands, enabling attackers with Administrator privileges to inject malicious commands into the underlying operating system. While the vulnerability requires local access and authenticated Administrator credentials, exploit code for this issue is publicly available. Cisco has stated that the flaw does not impact all ISE versions and has released patches for affected versions. No instances of the vulnerability being actively exploited in the wild have been reported. Additionally, other critical vulnerabilities have been addressed, including a backdoor account in the Smart Licensing Utility Windows software and CVE-2024-20295, a privilege escalation flaw in the Integrated Management Controller (IMC). A patch was issued for CVE-2024-20401, a flaw in Security Email Gateway (SEG) appliances that allowed attackers to add rogue root users and crash systems via malicious emails. Furthermore, a critical vulnerability in Smart Software Manager On-Prem (SSM On-Prem) license servers was highlighted, enabling attackers to modify any user’s password, including those of administrators.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Cisco ISE to version below:
| Cisco ISE Release | First Fixed Release |
| 3.1 and earlier | Not affected |
| 3.2 | 3.2P7 (Sep 2024) |
| 3.3 | 3.3P4 (Oct 2024) |
| 3.4 | Not affected |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]