CVE-2026-76460: Cisco Identity Services Engine
Cisco Identity Services Engine (ISE) และ Cisco ISE Passive Identity Connector (ISE-PIC) มีการใช้งานที่ไม่ถูกต้องของ APIs ที่ได้รับความเสี่ยงที่อาจทําให้เกิดการเชื่อมต่อที่ไม่รับรอง ผู้โจมตีระยะไกลเพื่อให้สามารถเข้าถึงอุปกรณ์ที่ได้รับผลกระทบโดยผ่านอินเตอร์เฟซการจัดการบนเว็บ
CISA (English)
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
- ผู้ผลิต
- Cisco
- ผลิตภัณฑ์
- Identity Services Engine
- ช่องโหว่
- Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- วันที่เพิ่ม
- 16 ก.ย. 2026
- กำหนดของ CISA (หน่วยงานรัฐบาลกลางสหรัฐฯ)
- 19 ก.ย. 2026
- การใช้ในการโจมตีด้วยแรนซัมแวร์
- ไม่ทราบ
- จุดอ่อน (CWE)
- CWE-648
แหล่งอ้างอิง
เว็บไซต์นี้สรุปแคตตาล็อกของ CISA เพื่อเป็นข้อมูลเท่านั้น ไม่ใช่คำแนะนำด้านความปลอดภัย โปรดปฏิบัติตามคำแนะนำของผู้ผลิตและประกาศอย่างเป็นทางการ
อัปเดตล่าสุด: · เวอร์ชันแคตตาล็อก 2026.10.02