Cisco Identity Services Engine SQL Injection Vulnerability


Description   (:An SQL injection vulnerability has been identified in the portal of Cisco Identity Services Engine (ISE).:A remote, authenticated attacker could exploit it via specially crafted HTTP POST requests containing SQL statements in order to view or delete notices (that may contain guest credentials in clear text) owned by other users of the system.::The vulnerability is due to insufficient validation of user-supplied input by the affected software.)
     
Vulnerable Products   Vulnerable OS:
Identity Services Engine (Cisco) - 1.4(0.908)
     
Solution   Cisco has released new versions of Identity Services Engine (ISE) which fix this vulnerability.
     
CVE   CVE-2017-3835
     
References   - CSCvb15627 : Cisco Identity Services Engine SQL Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-ise
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
SQL injection Prevention - POST : suspicious UPDATE statement in data
5.0.0
SQL injection Prevention - POST : suspicious SELECT statement in data
5.0.0
SQL injection Prevention - POST : suspicious DECLARE statement in data
5.0.0
SQL injection Prevention - POST : suspicious OPENROWSET statement in data
5.0.0
SQL injection Prevention - POST : suspicious OPENQUERY statement in data
5.0.0
SQL injection Prevention - POST : suspicious CAST statement in data
5.0.0
SQL injection Prevention - POST : suspicious EXEC statement in data
5.0.0
SQL injection Prevention - POST : suspicious CREATE statement in data
5.0.0
SQL injection Prevention - POST : suspicious INSERT statement in data
5.0.0
SQL injection Prevention - POST : suspicious DROP statement in data
5.0.0
SQL injection Prevention - POST : suspicious HAVING statement in data
5.0.0
SQL injection Prevention - POST : suspicious UNION statement in data
5.0.0
SQL injection Prevention - POST : suspicious OR statement in data
5.0.0
SQL injection Prevention - POST : possible version probing in data
5.0.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2017-02-15 

 Target Type 
Server 

 Possible exploit 
Remote