Cisco Hit by Second Zero-Day in One Week: Hackers Bypass ISE Authentication
Cisco has disclosed its second critical vulnerability in just one week, allowing hackers to bypass authentication on its Identity Services Engine (ISE). The ISE is a product that centralizes network access control for a large portion of the enterprise world. A zero-day exploit allows remote attackers to gain full control without credentials or user interaction.
The bug, rated 10 out of 10 in severity, affects all configurations of Cisco ISE and Cisco ISE Passive Identity Connector. There are no workarounds but upgrading to the latest software, which Cisco strongly recommends. The US Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its Known Exploited Vulnerabilities list, urging federal agencies to update within three days.
Cisco also fixed critical bugs in its Secure Firewall Management Center (FMC), but says it is not aware of any exploitation. However, firewalls are not immune, as multiple newly discovered critical bugs allow hackers to execute arbitrary commands with root privileges.