CVE Advisory- μ 체 κ³΅κ° Cisco ISE Path Traversal
Yoroi Advisory Teamμ 2022λ 7μ, Cisco Identity Services Engine(Ver. 3.1.0.518-Patch3-22042809)λ₯Ό λΆμνκΈ° μμνμΌλ©°, λκ° λ€νΈμν¬μ μ‘μΈμ€ν μ μλμ§, μΈμ μ‘μΈμ€ν μ μλμ§ λ±μ μ ννκ² μ μ΄νλ λ€νΈμν¬ κ΄λ¦¬ λꡬλ‘, μννΈμ¨μ΄ μ μ μ‘μΈμ€λ₯Ό 보μ₯νκ³ λ€νΈμν¬ μΈλΆνλ₯Ό μλνν©λλ€. CVE-2022-20822-κ²½λ‘ μ΄λ-CWE 22κ³Ό κ°μ μ·¨μ½μ μ΄ λ°κ²¬λμκ³ , μ μλ 7.1μ΄λ©° μν₯μ λλ€.
CVE Advisory - Full Disclosure Cisco ISE Path Traversal
Yoroi Advisory Team began to analyze Cisco Identity Services Engine (Ver. 3.1.0.518-Patch3-22042809) in July 2022, and network management that accurately controls who can access the network or when accessing the network and when accessing the network.As a tool, it ensures software definition access and automates network segmentation.A vulnerability such as CVE-2022-20822-Path-CWE 22 has been found, with a score of 7.1 and a high impact.
https://yoroi.company/en/research/cve-advisory-full-disclosure-cisco-ise-path-traversal/