CVE-2018-0277 (CNNVD-201805-630)
中文标题:
Cisco Identity Services Engine 安全漏洞
英文标题:
A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certifi...
漏洞描述
中文描述:
Cisco Identity Services Engine(ISE)是美国思科(Cisco)公司的一款基于身份的环境感知平台(ISE身份服务引擎)。该平台通过收集网络、用户和设备中的实时信息,制定并实施相应策略来监管网络。ISE Express是一款提供动态客户功能的使用在ISE中的捆绑包。ISE Virtual Appliance是一款ISE虚拟设备。 Cisco ISE、ISE Express和ISE Virtual Appliance中的Extensible Authentication Protocol-Transport Layer Security (EAP-TLS)证书验证存在安全漏洞,该漏洞源于程序没有充分的对客户端EAP-TLS证书执行输入验证。远程攻击者可利用该漏洞造成ISE应用程序服务器重启,导致拒绝服务。
英文描述:
A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incomplete input validation of the client EAP-TLS certificate. An attacker could exploit this vulnerability by initiating EAP authentication over TLS to the ISE with a crafted EAP-TLS certificate. A successful exploit could allow the attacker to restart the ISE application server, resulting in a DoS condition on the affected system. The ISE application could continue to restart while the client attempts to establish the EAP authentication connection. If an attacker attempted to import the same EAP-TLS certificate to the ISE trust store, it could trigger a DoS condition on the affected system. This exploit vector would require the attacker to have valid administrator credentials. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance. Cisco Bug IDs: CSCve31857.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | identity_services_engine | 2.0\(0.306\) | - | - |
cpe:2.3:a:cisco:identity_services_engine:2.0\(0.306\):*:*:*:*:*:*:*
|
| cisco | identity_services_engine | 2.0\(1.130\) | - | - |
cpe:2.3:a:cisco:identity_services_engine:2.0\(1.130\):*:*:*:*:*:*:*
|
| cisco | identity_services_engine | 2.1\(0.474\) | - | - |
cpe:2.3:a:cisco:identity_services_engine:2.1\(0.474\):*:*:*:*:*:*:*
|
| cisco | identity_services_engine | 2.2\(0.470\) | - | - |
cpe:2.3:a:cisco:identity_services_engine:2.2\(0.470\):*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2018-0277 |
2025-11-11 15:19:35 | 2025-11-11 07:34:56 |
| NVD | nvd_CVE-2018-0277 |
2025-11-11 14:55:54 | 2025-11-11 07:43:33 |
| CNNVD | cnnvd_CNNVD-201805-630 |
2025-11-11 15:10:01 | 2025-11-11 07:53:45 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 信任管理问题
- cnnvd_id: 未提取 -> CNNVD-201805-630
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 8.6
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']