Description
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized read access to sensitive RADIUS Policy details that are restricted for their role.
Problem types
Product status
3.3.0
3.3 Patch 2
3.3 Patch 1
3.3 Patch 3
3.4.0
3.3 Patch 4
3.4 Patch 1
3.3 Patch 5
3.3 Patch 6
3.4 Patch 2
3.3 Patch 7
3.4 Patch 3
3.5.0
3.4 Patch 4
3.3 Patch 8
3.5 Patch 1
3.3 Patch 9
3.4 Patch 5
3.5 Patch 3
3.5 Patch 2
3.3 Patch 10
References
sec.cloudapps.cisco.com/...sco-sa-ise-unauth-bypass-uxjRXGpb (cisco-sa-ise-unauth-bypass-uxjRXGpb)