CVE-2018-15425

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.

Risk Information

Base Score
4.7
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.294

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities in Cisco Identity Services Engine For Cisco Identity Services EngineNCM
Deserialization of Untrusted Data Vulnerability (CVE-2018-15425)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706002Security Update for Cisco Identity Services Engine 2.0(0.905)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234