Cisco ISE FLAW of maximum severity allows hackers to execute the root code


  • Cisco has corrected an identity identity engine impacting on a maximum severity flaw and an ISE passive identity connector
  • The defect has enabled threat stakeholders to execute an arbitrary code on the underlying operating system
  • It was corrected in versions 3.3 and 3.4

Vulnerability of maximum severity has been recently discovered and corrected, in Cisco Identity Services Engine (ISE) and ISE Identity Connector (ISE-PIC). This defect allowed threat stakeholders to execute arbitrary code, with high privileges, on the operating system of the devices performing the tools.

ISE is a network safety and access control policies platform, helping organizations to manage centrally which and what can connect to their network. ISE-PIC, on the other hand, is a light service that collects identity information on users and devices without obliging it to authenticate themselves via traditional methods.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top