Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks.
These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the affected device.
Metrics
Affected Vendors & Products
References
History
Tue, 27 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cisco
Cisco identity Services Engine Software |
|
CPEs | cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:* | |
Vendors & Products |
Cisco
Cisco identity Services Engine Software |
|
Metrics |
ssvc
|
Wed, 21 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the affected device. | |
Title | Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabities | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cisco
Published: 2024-08-21T19:16:43.196Z
Updated: 2024-08-27T13:43:25.274Z
Reserved: 2023-11-08T15:08:07.663Z
Link: CVE-2024-20417
Vulnrichment
Updated: 2024-08-27T13:42:48.782Z
NVD
Status : Awaiting Analysis
Published: 2024-08-21T20:15:08.533
Modified: 2024-08-22T12:48:02.790
Link: CVE-2024-20417
Redhat
No data.