Cisco Identity Services Engine REST API Blind SQLi (cisco-sa-ise-rest-5bPKrNtZ)

medium Nessus Plugin ID 206882

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabilities is affected by a Blind SQL Injection (SQLi) vulnerability.

- Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the affected device. (CVE-2024-20417)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwj94294, CSCwj94297, CSCwj94305, CSCwj94315

See Also

http://www.nessus.org/u?7be112f7

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj94294

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj94297

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj94305

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwj94315

Plugin Details

Severity: Medium

ID: 206882

File Name: cisco-sa-ise-rest-5bPKrNtZ.nasl

Version: 1.3

Type: local

Family: CISCO

Published: 9/10/2024

Updated: 9/17/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: High

Base Score: 7.7

Temporal Score: 5.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:N

CVSS Score Source: CVE-2024-20417

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 8/21/2024

Vulnerability Publication Date: 8/21/2024

Reference Information

CVE: CVE-2024-20417

CWE: 89

CISCO-SA: cisco-sa-ise-rest-5bPKrNtZ

IAVA: 2024-A-0414-S

CISCO-BUG-ID: CSCwj94294, CSCwj94297, CSCwj94305, CSCwj94315