CVE Advisory- ์ „์ฒด ๊ณต๊ฐœ Cisco ISE Broken Access Control

CVE Advisory- ์ „์ฒด ๊ณต๊ฐœ Cisco ISE Broken Access Control

๊ฐ€ ์ž˜๋ชป๋˜์—ˆ๊ฑฐ๋‚˜ ๊ตฌ์„ฑ๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์•ก์„ธ์Šค ์ œ์–ด ์ •์ฑ…์ด ์ž˜๋ชป ์ ์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Saguri๋Š” Cisco ISE 3.1.0.518-PATCH3-22042809์˜ ๋ถ„์„์„ ์‹œ์ž‘ํ•˜์˜€๊ณ , Cisco ISE๋Š” ์ž์ฒด ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ๋„๊ตฌ๋กœ, ์—ญ๋™์ ์ด๊ณ  ์ž๋™ํ™”๋œ ๋ณด์•ˆ ๋ฐ ๊ด€๋ฆฌ ์ •์ฑ… ๋ฐฉ์‹์œผ๋กœ ์ ์šฉํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ์ œ์–ด ๋ฐฐํฌ๋ฅผ ๋‹จ์ˆœํ™”ํ•ฉ๋‹ˆ๋‹ค. OWASP ์นดํ…Œ๊ณ ๋ฆฌ A01- ๊นจ์ง„ ์•ก์„ธ์Šค ์ œ์–ด์— ์˜ํ•ด ๋†’์€ ์ ์ˆ˜๋ฅผ ๋ฐ›์•˜๊ณ , ์ž˜๋ชป๋œ ๋งค๊ฐœ ๋ณ€์ˆ˜๋‚˜ ๊ตฌ์„ฑ์— ์˜ํ•ด ์•ก์„ธ์Šค ์ œ์–ด ์ •์ฑ…์ด ์ž˜๋ชป ์ ์šฉ๋  ์ˆ˜ ์žˆ๋‹ค.

Saguri๊ฐ€ Cisco ISE 3.1.0.518-PATCH3-22042809์˜ ๋ถ„์„์„ ์‹œ์ž‘ํ•˜์—ฌ ์ž์ฒด ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ๋„๊ตฌ๋กœ ์—ญ๋™์ ์ด๊ณ  ์ž๋™ํ™”๋œ ๋ณด์•ˆ ๋ฐ ๊ด€๋ฆฌ ์ •์ฑ… ๋ฐฉ์‹์œผ๋กœ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค ์ œ์–ด ๋ฐฐํฌ๋ฅผ ๋‹จ์ˆœํ™”ํ•˜๋Š” Cisco ISE๋ฅผ ๋ถ„์„ํ•˜์˜€๊ณ , OWASP ์นดํ…Œ๊ณ ๋ฆฌ A01- ๊นจ์ง„ ์•ก์„ธ์Šค ์ œ์–ด๋ฅผ ํ†ตํ•ด ๋†’์€ ์ ์ˆ˜๋ฅผ ๋ฐ›์•˜์œผ๋ฉฐ, ๋งค๊ฐœ ๋ณ€์ˆ˜๋‚˜ ๊ตฌ์„ฑ์ด ์ž˜๋ชป๋˜๋ฉด ์•ก์„ธ์Šค ์ œ์–ด ์ •์ฑ…์ด ์ž˜๋ชป ์ ์šฉ๋  ์ˆ˜ ์žˆ๋‹ค.

CVE Advisory - Full Disclosure Cisco ISE Broken Access Control

Because it is wrong or organized, the access control policy can be wrong.

Saguri began analysis of Cisco ISE 3.1.0.518-Patch3-22042809, and CISCO ISE is a tool for its own network management, which is applied to a dynamic and automated security and management policy method to simplify network access control distribution.OWASP category A01-A high score was obtained by a broken access control, and the wrong parameters or configuration can be incorrectly applied.

Saguri began analyzing Cisco ISE 3.1.0.518-Patch3-22042809 and analyzed Cisco ISE that simplified network access control distribution by dynamic and automated security and management policy as a tool for its own network management and OWASP category A01-It has received high scores through broken access control, and if the parameters or configuration are wrong, the access control policy can be incorrectly applied.

https://yoroi.company/research/cve-advisory-full-disclosure-cisco-ise-broken-access-control/