当前位置:网站首页>Cloud security daily 220714: Cisco identity service engine found an authentication bypass vulnerability and needs to be upgraded as soon as possible
Cloud security daily 220714: Cisco identity service engine found an authentication bypass vulnerability and needs to be upgraded as soon as possible
2022-07-27 23:06:00 【TechWeb】
Cisco Identity Services Engine(ISE) It's Cisco (Cisco) The company's identity based environment awareness platform (ISE Identity service engine ). The platform collects data through the network 、 Real time information in users and devices , Develop and implement strategies to monitor the network .Cisco ISE Be able to gain insight into all attacks on the network , And can reduce the pressure of complex access management .
7 month 13 Japan , Cisco has released a security update , Repair the Cisco ISE Authentication bypass vulnerability found in the engine . Here are the details of the vulnerability :
Vulnerability Details
source :
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-SAML-nuukMPf9
CVE-2022-20733 CVSS score : 5.3 severity : secondary
Cisco identity service engine (ISE) A vulnerability in the login page may allow unauthenticated remote attackers to log in without credentials and have unrestricted access to all roles .
This vulnerability is due to the exposure of sensitive security assertion markup language (SAML) Metadata . Attackers can use exposed SAML Metadata bypasses authentication of the user portal to exploit this vulnerability . Successful exploitation allows attackers to access all roles without any restrictions .
Affected products
Cisco ISE 3.1 edition
Solution
Cisco ISE 3.1 Version update 3.1 Patch 3 Can repair
View more vulnerability information And upgrade, please visit the official website :
https://tools.cisco.com/security/center/publicationListing.x
边栏推荐
- 2022 / 4 / 11 exam summary
- UDF and analysis cases of sparksql, 220726,,
- 细胞CLE19多肽荧光成像牛血清白蛋白荧光猝灭量子点的制备
- The follow-up is coming. Whether it's OK without reference, let's make it clear to everyone at once!
- Android 11 security policy and permission management
- 联合省选2022复习计划
- MediaTek and Samsung launched the world's first 8K TV that supports Wi Fi 6
- 2022/4/8考试总结
- 紫光FPGA解决口罩难题!助力口罩生产全面提速
- Bubbling, fast sorting, heap sorting and cardinality sorting of the eight sorts
猜你喜欢

一篇搞定Redis中的BigKey问题

Jeninkins离线部署

深度剖析 —— 文件操作

Fluorescence imaging of cle19 polypeptide in cells preparation of fluorescence quenching quantum dots of bovine serum albumin

Cloudcompare & PCL platform convex hull method to calculate crown volume

干货|语义网、Web3.0、Web3、元宇宙这些概念还傻傻分不清楚?(中)

What is the b+tree index of MySQL? How does the cluster index grow?

Redis网红高频面试题三连:缓存穿透?缓存击穿?缓存雪崩?

PyQt5快速开发与实战 4.9 对话框类控件

Cron expression
随机推荐
Take you to master makefile analysis
2022 / 4 / 11 exam summary
深度剖析 —— 文件操作
Cloudcompare & PCL point cloud equally spaced slices
leetcode-470.用 Rand7() 实现 Rand10()
Exam summary on May 13, 2022
初中三年回忆录
ADI, Shijian and Junlong technology jointly donated 2.3 million yuan to help fight the epidemic in Hubei
JVM composition and memory model
You don't know about redis. Let me explain the underlying data structure of redis in detail
[noi2018] return (Kruskal reconstruction tree / persistent and search set)
摩托罗拉诉海能达案一审结果出炉:海能达被判赔53亿元
传英特尔明年将采用台积电6nm EUV工艺
Arm32 for remote debugging
Metersphere financial company landing experience sharing
MeterSphere金融公司落地经验分享
PyQt5快速开发与实战 4.9 对话框类控件
你不知道的Redis那些事,我来详解Redis底层数据结构
2022/6/9 考试总结
带你掌握 Makefile 分析