⚪ Advisory | Multiple High Severity Vulnerabilities in Cisco Products:
▫️CVE-2022-20961: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct CSRF attack and perform arbitrary actions on an affected device.
▫️CVE-2022-20868: A Privilege Escalation vulnerability. An attacker could exploit it by authenticating to an affected device & sending a crafted HTTP request. A successful exploit could allow the attacker to impersonate another valid user & execute commands.
The vulnerability allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page to execute arbitrary commands on the victim machine.
Update to the latest version.
🔗 https://t.co/U5MTNvYooH