CVE Advisory- ์ „์ฒด ๊ณต๊ฐœ Cisco ISE Broken Access Control - Yoroi

CVE Advisory- ์ „์ฒด ๊ณต๊ฐœ Cisco ISE Broken Access Control

Cisco ISE๋Š” ์ž์ฒด ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ๋„๊ตฌ๋กœ์„œ ๋ณด์•ˆ ๋ฐ ๊ด€๋ฆฌ ์ •์ฑ…์„ ์ž๋™ํ™”ํ•˜๊ณ  ์—ญ๋™์ ์œผ๋กœ ์ ์šฉํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ์ œ์–ด๋ฅผ ๋‹จ์ˆœํ™”ํ•ฉ๋‹ˆ๋‹ค. ISE๋Š” ๋ˆ„๊ฐ€ ๋„คํŠธ์›Œํฌ์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š”์ง€, ์–ธ์ œ, ์–ด๋–ป๊ฒŒ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ๋“ฑ์˜ ์ •๋ณด๋ฅผ ๊ฐ€์‹œํ™”ํ•˜๊ณ  ์†Œํ”„ํŠธ์›จ์–ด๋กœ ์ •์˜๋œ ์•ก์„ธ์Šค ๋ฐ AU- ํ† ๋ฉ”์ดํŠธ ๋„คํŠธ์›Œํฌ ์„ธ๋ถ„ํ™”๋ฅผ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ Saguri๋Š” Cisco Identity Service Engine-3.1.0.518-PATCH3-22042809 ๋ถ„์„์„ ํ†ตํ•ด ๋‚ด๋ถ€ ํ”„๋กœ์ ํŠธ๋ฅผ ์‹œ์ž‘ํ–ˆ์Šต๋‹ˆ๋‹ค.

Cisco ISE๋Š” ์ž์ฒด ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ๋„๊ตฌ๋กœ ๋ณด์•ˆ ๋ฐ ๊ด€๋ฆฌ ์ •์ฑ…์„ ์ž๋™ํ™”ํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ์ œ์–ด๋ฅผ ๋‹จ์ˆœํ™”ํ•˜๊ณ , ๋ˆ„๊ฐ€ ๋„คํŠธ์›Œํฌ์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š”์ง€, ์–ธ์ œ, ์–ด๋–ป๊ฒŒ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ๋“ฑ์˜ ์ •๋ณด๋ฅผ ๊ฐ€์‹œํ™”ํ•˜๊ณ  ์†Œํ”„ํŠธ์›จ์–ด๋กœ ์ •์˜๋œ ์•ก์„ธ์Šค ๋ฐ AU-ํ† ๋ฉ”์ดํŠธ ๋„คํŠธ์›Œํฌ ์„ธ๋ถ„ํ™”๋ฅผ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. Saguri๋Š” Cisco Identity Service Engine-3.1.0.518-PATCH3-22042809๋ฅผ ๋ถ„์„ํ•˜์—ฌ ๋‚ด๋ถ€ ํ”„๋กœ์ ํŠธ๋ฅผ ์‹œ์ž‘ํ–ˆ์Šต๋‹ˆ๋‹ค.

CVE Advisory - Full Disclosure Cisco ISE Broken Access Control

CISCO ISE is a tool for managing its own network, automating security and management policies and applying it dynamically to simplify network access control.ISE visible information such as who can access the network, when and how to access it, and guarantees subdivision of access and AU-Tomate networks defined as software.Currently, Saguri has started an internal project through an analysis of Cisco Identity Service Engine-3.1.0.518-Patch3-22042809.

CISCO ISE is a tool for management of its own network, automating security and management policies, simplifying network access control, visualizing information such as who can access the network, when, and how to access it, and access it as a software.And AU-Tomate Network Segmentation.Saguri started the internal project by analyzing Cisco Identity Service Engine-3.1.0.518-Patch3-22042809.

https://yoroi.company/en/research/cve-advisory-full-disclosure-cisco-ise-broken-access-control/