Attackers are exploiting a Cisco ISE authentication bypass that can end in root command execution.
The path needs management-plane reachability but no credentials or user interaction.
Cisco Identity Services Engine and ISE Passive Identity Connector, network-access-control systems deployed as appliances or virtual machines.
Unauthenticated root command execution on a network-access-control appliance
Observed exploitation turns the management-plane authentication failure into a current root risk, although the interface must be reachable.
Detail and 5 sources
A crafted unauthenticated API request bypasses the web management interface; Cisco says successful exploitation may then produce root command execution.
Cisco and the Canadian Cyber Centre identify fixed releases, and both record the exploitation.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- No