logo

Cisco fixes root escalation vulnerability with public exploit code

ID: 90194497-c2b8-51bd-a02b-1c6a19578f50

STIX ID: report--90194497-c2b8-51bd-a02b-1c6a19578f50

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2024-09-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco patched an OS command injection vulnerability (CVE-2024-20469) in Identity Services Engine (ISE) that allows an authenticated local attacker to inject CLI commands and escalate to root; proof-of-concept exploit code is public but exploitation requires prior Administrator access on unpatched systems, and Cisco reports no observed in-the-wild exploitation while providing fixed releases for affected 3.2 and 3.3 versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.