Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-27122 – A vulnerability in the Microsoft Active Directory integration of Cisco Id

A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator account on an affected device. The vulnerability is due to incorrect privilege assignment. An attacker could exploit this vulnerability by logging in to the system with a crafted Active Directory account. A successful exploit could allow the attacker to obtain root privileges on an affected device.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27122

Reference (s):

  • CISCO:20201104 Cisco Identity Services Engine Privilege Escalation Vulnerability
  • URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-priv-esc-fNZX8hHj
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5980 - The Genertel (aka com.genertel) application 2.6.0 for Android does not ve

2021-current

CVE-2019-7853 - A stored cross-site scripting vulnerability exists in Magento 2.1 prior t

2021-current

CVE-2020-1161 - A denial of service vulnerability exists when ASP.NET Core improperly han