Cisco plugs two Identity Services Engine security holes • The Register
Cisco has fixed two critical vulnerabilities in its Identity Services Engine (ISE) that could allow an authenticated remote attacker to execute arbitrary commands as root or access sensitive information, modify configurations, and reload affected devices. As if requiring authentication wasn’t a hurdle enough: Exploiting either of these 9.9 and 9.1-out-of-10-severity-rated bugs requires valid read-only administrative … Read more