06-20-2018 06:57 AM - edited 03-20-2019 10:14 PM
Will probably open a TAC on this but wanted to ask first. Is ISE 2.3(0.298) affected by this vulnerability regardless on installed platform? And if yes is the only resolution path an "upgrade" to 2.4?
The bug ID states version 2.3(0.298) is affected but only when installed on "Cisco Identity Services Engine (ISE) 3300 Series Appliances." However due to the bug ID wording vulnerability scanners are flagging 2.3(0.298) as vulnerable regardless of the installed platform with the only option an upgrade to 2.4. Problem; 2.3 is still receiving updates, but this bug ID is not noted anywhere in the current release notes of either 2.3 (dated 8 June 2018) or, for that matter, 2.4 release notes (dated 3 May 2018.)
08-29-2018 05:48 AM
Hello,
I was just curious if TAC provided any feedback on this. We just installed a new 2.3 environment and our scanners flagged the same vulnerability.
08-29-2018 08:44 AM
I was told to upgrade to 2.4 by TAC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide