CVE-2026-20146

Alapadatok

Súlyosság: Közepes

CVSS vektor: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N

CVSS base score: 5.5

Kihasználhatóság:

  • Hálózatról kihasználható
  • Alacsony komplexitás
  • Magas jogosultság szükséges
  • Nem szükséges felhasználói interakció

Következmények

Loss of availability (Elérhetőség elvesztése)
Loss of confidentiality (Bizalmasság elvesztése)
Loss of integrity (Sértetlenség elvesztése)

Publikálás dátuma: 2026.07.17.

Érintett rendszerek: CISCO Identity Services Engine

CWE: CWE-22

Leírás

A szoftver külső bemenetet használ a korlátozott szülőkönyvtár alatt található fájl vagy könyvtár azonosítására szolgáló helynév megalkotásához, de a szoftver nem megfelelően semlegesíti azokat a speciális elemeket az értékben, amelyek az útvonalat olyan helyre irányítják, amely a korlátozott könyvtáron kívül van.

Megjegyzés: A leírás a CWE-besorolás magyar fordítása. Bővebb információért kattintson az Alapadatok CWE elemére.

Érintett rendszerek és verzióik

Cisco ISE Passive Identity Connector 3.1.0
Cisco ISE Passive Identity Connector 3.2.0
Cisco Identity Services Engine Software 3.1.0 p3
Cisco Identity Services Engine Software 3.3 Patch 10
Cisco Identity Services Engine Software 3.2.0 p1
Cisco ISE Passive Identity Connector 3.3.0
Cisco ISE Passive Identity Connector 3.4.0
Cisco Identity Services Engine Software 3.3 Patch 5
Cisco Identity Services Engine Software 3.2.0
Cisco Identity Services Engine Software 3.2.0 p7
Cisco Identity Services Engine Software 3.1.0 p2
Cisco Identity Services Engine Software 3.2.0 p2
Cisco Identity Services Engine Software 3.4 Patch 2
Cisco Identity Services Engine Software 3.3.0
Cisco Identity Services Engine Software 3.1.0 p10
Cisco Identity Services Engine Software 3.3 Patch 8
Cisco Identity Services Engine Software 3.3 Patch 6
Cisco Identity Services Engine Software 3.1.0 p5
Cisco Identity Services Engine Software 3.4 Patch 5
Cisco Identity Services Engine Software 3.2.0 p5
Cisco Identity Services Engine Software 3.1.0 p6
Cisco Identity Services Engine Software 3.2.0 p3
Cisco Identity Services Engine Software 3.1.0 p9
Cisco Identity Services Engine Software 3.1.0 p4
Cisco Identity Services Engine Software 3.3 Patch 4
Cisco Identity Services Engine Software 3.1.0 p8
Cisco ISE Passive Identity Connector 3.5.0
Cisco Identity Services Engine Software 3.4.0
Cisco Identity Services Engine Software 3.2 Patch 9
Cisco Identity Services Engine Software 3.4 Patch 3
Cisco Identity Services Engine Software 3.5 Patch 1
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.2.0 p6
Cisco Identity Services Engine Software 3.5 Patch 3
Cisco Identity Services Engine Software 3.2 Patch 8
Cisco Identity Services Engine Software 3.4 Patch 1
Cisco Identity Services Engine Software 3.4 Patch 4
Cisco Identity Services Engine Software 3.3 Patch 7
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.3 Patch 2
Cisco Identity Services Engine Software 3.3 Patch 1
Cisco Identity Services Engine Software 3.5.0
Cisco Identity Services Engine Software 3.3 Patch 3
Cisco Identity Services Engine Software 3.2.0 p4
Cisco Identity Services Engine Software 3.5 Patch 2
Cisco Identity Services Engine Software 3.3 Patch 9
Cisco Identity Services Engine Software 3.1.0 p7

Hivatkozások

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y
https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20146