Cisco Patches Dozens of Critical-Severity Flaws in FMC, ISE, and Nexus Dashboard
Cisco has released patches for dozens of critical-severity vulnerabilities in its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws.
Three of the issues have already been publicly disclosed by Cisco, which warns that they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three vulnerabilities.
Cisco's advisories detail six other critical-severity ISE vulnerabilities: three remote code execution (RCE) issues, two command injection flaws leading to command execution with root privileges, and an authentication bypass in the REST API.