Start your day with intelligence. Get The OODA Daily Pulse.
Cisco patches critical ISE flaw allowing command execution and data exposure.
Cisco fixed a critical input‑validation bug in ISE and ISE‑PIC that lets attackers with admin credentials run commands on the underlying OS and potentially escalate to root. The update also resolves a high‑severity issue that exposed sensitive data, including hashed credentials, to unauthenticated users. Additional medium‑severity flaws in Webex, Umbrella Virtual Appliance, and Crosswork Network Controller were patched, and Cisco says none of the issues are known to be exploited.
Read more:
https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/