CVE Advisory- ๋ถ๋ถ ๊ณต๊ฐ Cisco ISE Broken Access Control
Saguri๋ Cisco Identity Service Engine-3.1.0.518-PATCH3-22042809์ ๋ถ์์ ์์ํ์ผ๋ฉฐ Cisco ISE๋ ์์ฒด ๋คํธ์ํฌ ๊ด๋ฆฌ ๋๊ตฌ๋ก์ ์ญ๋์ ์ด๊ณ ์๋ํ ๋ ๋ณด์ ๋ฐ '๊ด๋ฆฌโ์ ์ฑ ๋ฐฉ์์ผ๋ก ๋คํธ์ํฌ ์ก์ธ์ค ์ ์ด ๊ตฌํ ๋ฐ ๋ฐฐํฌ๋ฅผ ๋จ์ํํฉ๋๋ค. ISE๋ ๊ฐ์ ์ ๋ณด์ฅํ๊ณ ํ์ฉํ๋ฉฐ ๋๊ฐ, ์ด๋ค ์ก์ธ์ค๋ฅผ ํ ์ ์๋์ง, ์ธ์ ๋ฐ ์ด๋ป๊ฒ ์ก์ธ์ค ํ ์ ์๋์ง๋ฅผ ๋ณด์ฅํฉ๋๋ค. ๋ํ, ์ํํธ์จ์ด๋ก ์ ์๋ ์ก์ธ์ค ๋ฐ AU-ํ ๋ฉ์ดํธ ๋คํธ์ํฌ ์ธ๋ถํ ๋ฐ ๋คํธ์ํฌ ์ํ ๊ฐ์์ฑ์ ์ ๊ณตํฉ๋๋ค. CVE-2022-20956-๊นจ์ง ์ก์ธ์ค ์ ์ด-CWE 648 CVE-20๋ฅผ ํฌํจํฉ๋๋ค.
Saguri๊ฐ Cisco ISE๋ฅผ ๋ถ์ํ๋ฉด์ ๋คํธ์ํฌ ์ก์ธ์ค ์ ์ด ๊ตฌํ ๋ฐ ๋ฐฐํฌ๋ฅผ ๋จ์ํํ๊ณ , ๊ฐ์ ์ ๋ณด์ฅํ๊ณ ํ์ฉํ๋ฉฐ ์ํํธ์จ์ด๋ก ์ ์๋ ์ก์ธ์ค ๋ฐ AU-ํ ๋ฉ์ดํธ ๋คํธ์ํฌ ์ธ๋ถํ ๋ฐ ๋คํธ์ํฌ ์ํ ๊ฐ์์ฑ์ ์ ๊ณตํฉ๋๋ค. ์ด์ ๋ํ ์ ๋ณด๋ Cisco security advisory, NVD ๋ฐ CVE-2022-20956-๊นจ์ง ์ก์ธ์ค ์ ์ด-CWE 648 CVE-20๋ฅผ ํฌํจํฉ๋๋ค.
CVE Advisory - Partial Disclosure Cisco ISE Broken Access Control
Saguri began analyzing Cisco Identity Service Engine-3.1.0.518-Patch3-22042809, and Cisco ISE is its own network management tool that simplifies network access control and distribution with dynamic and automated security and โmanagementโ policy.ISE guarantees and allows, and guarantees who can, which access, when and how to access it.It also provides access and AU-Tomate network segmentation and network status visibility defined by software.CVE-2022-20956-broken access control-CWE 648 CVE-20.
Saguri analyzes Cisco ISE, simplifies network access control and distribution, guarantees and allows intervention, and provides access to access and AU-Tomate networks defined as software, and provides network status visibility.Information on this includes Cisco Security Advisory, NVD and CVE-2022-20956-Broken Access Control-CWE 648 CVE-20.
https://yoroi.company/en/research/cve-advisory-partial-disclosure-cisco-ise-broken-access-control/