CVE-2024-20531
MEDIUMDescription
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.
Is your site exposed to CVE-2024-20531?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
References
Frequently Asked Questions
What is CVE-2024-20531? +
How severe is CVE-2024-20531? +
What products are affected by CVE-2024-20531? +
How do I check if I'm vulnerable to CVE-2024-20531? +
Related Vulnerabilities
LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's bucket …
Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, …
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects …
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) …
PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version …
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain places, …