Cisco fixes root escalation vulnerability with public exploit code
ID: 90194497-c2b8-51bd-a02b-1c6a19578f50
STIX ID: report--90194497-c2b8-51bd-a02b-1c6a19578f50
Feed Name: Bleeping Computer
Threat Score
Cisco patched an OS command injection vulnerability (CVE-2024-20469) in Identity Services Engine (ISE) that allows an authenticated local attacker to inject CLI commands and escalate to root; proof-of-concept exploit code is public but exploitation requires prior Administrator access on unpatched systems, and Cisco reports no observed in-the-wild exploitation while providing fixed releases for affected 3.2 and 3.3 versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
