Cisco Identity Services Engine... Note

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Multiple vulnerabilities exist in the Cisco Identity Services Engine and its Passive Identity Connector web-based management interfaces. These flaws allow an authenticated, remote attacker to alter certain configuration elements. The root cause is insufficient server-side validation of administrator permissions. An attacker would need valid administrator credentials to exploit these issues. By sending a specially crafted HTTP request, an attacker could succeed. The successful exploitation permits modification of file descriptions on specific pages. Cisco has addressed these vulnerabilities through software updates. No workarounds are currently available to mitigate these security risks. The security impact rating for these vulnerabilities is considered Medium. Further details and advisories can be found on Cisco's security center.