CVE Advisory- ์ ์ฒด ๊ณต๊ฐ Cisco ISE Broken Access Control
๊ฐ ์๋ชป๋์๊ฑฐ๋ ๊ตฌ์ฑ๋์๊ธฐ ๋๋ฌธ์ ์ก์ธ์ค ์ ์ด ์ ์ฑ ์ด ์๋ชป ์ ์ฉ๋ ์ ์์ต๋๋ค.
Saguri๋ Cisco ISE 3.1.0.518-PATCH3-22042809์ ๋ถ์์ ์์ํ์๊ณ , Cisco ISE๋ ์์ฒด ๋คํธ์ํฌ ๊ด๋ฆฌ๋ฅผ ์ํ ๋๊ตฌ๋ก, ์ญ๋์ ์ด๊ณ ์๋ํ๋ ๋ณด์ ๋ฐ ๊ด๋ฆฌ ์ ์ฑ ๋ฐฉ์์ผ๋ก ์ ์ฉํ์ฌ ๋คํธ์ํฌ ์ก์ธ์ค ์ ์ด ๋ฐฐํฌ๋ฅผ ๋จ์ํํฉ๋๋ค. OWASP ์นดํ ๊ณ ๋ฆฌ A01- ๊นจ์ง ์ก์ธ์ค ์ ์ด์ ์ํด ๋์ ์ ์๋ฅผ ๋ฐ์๊ณ , ์๋ชป๋ ๋งค๊ฐ ๋ณ์๋ ๊ตฌ์ฑ์ ์ํด ์ก์ธ์ค ์ ์ด ์ ์ฑ ์ด ์๋ชป ์ ์ฉ๋ ์ ์๋ค.
Saguri๊ฐ Cisco ISE 3.1.0.518-PATCH3-22042809์ ๋ถ์์ ์์ํ์ฌ ์์ฒด ๋คํธ์ํฌ ๊ด๋ฆฌ๋ฅผ ์ํ ๋๊ตฌ๋ก ์ญ๋์ ์ด๊ณ ์๋ํ๋ ๋ณด์ ๋ฐ ๊ด๋ฆฌ ์ ์ฑ ๋ฐฉ์์ผ๋ก ๋คํธ์ํฌ ์ก์ธ์ค ์ ์ด ๋ฐฐํฌ๋ฅผ ๋จ์ํํ๋ Cisco ISE๋ฅผ ๋ถ์ํ์๊ณ , OWASP ์นดํ ๊ณ ๋ฆฌ A01- ๊นจ์ง ์ก์ธ์ค ์ ์ด๋ฅผ ํตํด ๋์ ์ ์๋ฅผ ๋ฐ์์ผ๋ฉฐ, ๋งค๊ฐ ๋ณ์๋ ๊ตฌ์ฑ์ด ์๋ชป๋๋ฉด ์ก์ธ์ค ์ ์ด ์ ์ฑ ์ด ์๋ชป ์ ์ฉ๋ ์ ์๋ค.
CVE Advisory - Full Disclosure Cisco ISE Broken Access Control
Because it is wrong or organized, the access control policy can be wrong.
Saguri began analysis of Cisco ISE 3.1.0.518-Patch3-22042809, and CISCO ISE is a tool for its own network management, which is applied to a dynamic and automated security and management policy method to simplify network access control distribution.OWASP category A01-A high score was obtained by a broken access control, and the wrong parameters or configuration can be incorrectly applied.
Saguri began analyzing Cisco ISE 3.1.0.518-Patch3-22042809 and analyzed Cisco ISE that simplified network access control distribution by dynamic and automated security and management policy as a tool for its own network management and OWASP category A01-It has received high scores through broken access control, and if the parameters or configuration are wrong, the access control policy can be incorrectly applied.
https://yoroi.company/research/cve-advisory-full-disclosure-cisco-ise-broken-access-control/