Alapadatok
Súlyosság: Közepes
CVSS vektor: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
CVSS base score: 5.5
Kihasználhatóság:
- Hálózatról kihasználható
- Alacsony komplexitás
- Magas jogosultság szükséges
- Nem szükséges felhasználói interakció
Következmények
Loss of availability (Elérhetőség elvesztése)
Loss of confidentiality (Bizalmasság elvesztése)
Loss of integrity (Sértetlenség elvesztése)
Leírás
A szoftver külső bemenetet használ a korlátozott szülőkönyvtár alatt található fájl vagy könyvtár azonosítására szolgáló helynév megalkotásához, de a szoftver nem megfelelően semlegesíti azokat a speciális elemeket az értékben, amelyek az útvonalat olyan helyre irányítják, amely a korlátozott könyvtáron kívül van.
Megjegyzés: A leírás a CWE-besorolás magyar fordítása. Bővebb információért kattintson az Alapadatok CWE elemére.Érintett rendszerek és verzióik
Cisco ISE Passive Identity Connector 3.1.0
Cisco ISE Passive Identity Connector 3.2.0
Cisco Identity Services Engine Software 3.1.0 p3
Cisco Identity Services Engine Software 3.3 Patch 10
Cisco Identity Services Engine Software 3.2.0 p1
Cisco ISE Passive Identity Connector 3.3.0
Cisco ISE Passive Identity Connector 3.4.0
Cisco Identity Services Engine Software 3.3 Patch 5
Cisco Identity Services Engine Software 3.2.0
Cisco Identity Services Engine Software 3.2.0 p7
Cisco Identity Services Engine Software 3.1.0 p2
Cisco Identity Services Engine Software 3.2.0 p2
Cisco Identity Services Engine Software 3.4 Patch 2
Cisco Identity Services Engine Software 3.3.0
Cisco Identity Services Engine Software 3.1.0 p10
Cisco Identity Services Engine Software 3.3 Patch 8
Cisco Identity Services Engine Software 3.3 Patch 6
Cisco Identity Services Engine Software 3.1.0 p5
Cisco Identity Services Engine Software 3.4 Patch 5
Cisco Identity Services Engine Software 3.2.0 p5
Cisco Identity Services Engine Software 3.1.0 p6
Cisco Identity Services Engine Software 3.2.0 p3
Cisco Identity Services Engine Software 3.1.0 p9
Cisco Identity Services Engine Software 3.1.0 p4
Cisco Identity Services Engine Software 3.3 Patch 4
Cisco Identity Services Engine Software 3.1.0 p8
Cisco ISE Passive Identity Connector 3.5.0
Cisco Identity Services Engine Software 3.4.0
Cisco Identity Services Engine Software 3.2 Patch 9
Cisco Identity Services Engine Software 3.4 Patch 3
Cisco Identity Services Engine Software 3.5 Patch 1
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.2.0 p6
Cisco Identity Services Engine Software 3.5 Patch 3
Cisco Identity Services Engine Software 3.2 Patch 8
Cisco Identity Services Engine Software 3.4 Patch 1
Cisco Identity Services Engine Software 3.4 Patch 4
Cisco Identity Services Engine Software 3.3 Patch 7
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.3 Patch 2
Cisco Identity Services Engine Software 3.3 Patch 1
Cisco Identity Services Engine Software 3.5.0
Cisco Identity Services Engine Software 3.3 Patch 3
Cisco Identity Services Engine Software 3.2.0 p4
Cisco Identity Services Engine Software 3.5 Patch 2
Cisco Identity Services Engine Software 3.3 Patch 9
Cisco Identity Services Engine Software 3.1.0 p7
Hivatkozások
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y
https://euvd.enisa.europa.eu/vulnerability/CVE-2026-20146
