cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
510
Views
2
Helpful
2
Replies

CSCwo99449 - ISE Unauthenticated Remote Code Execution Vulnerability

takuya.hokazono
Level 1
Level 1

Please clarify the requirements to mitigate the Vulnerability.
3.3.0.430-Patch6 is enough to mitigate the Vulnerability or required ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz even if ISE is work in 3.3.0.430-Patch6.

image.png

 

2 Replies 2

takuya.hokazono
Level 1
Level 1

No release note for P6 now but Patch 6 is fixed release in Bug search tool so I'm gonna patch up to P6. But it's helpful if someone answers to my question.
https://bst.cisco.com/bugsearch/bug/CSCwo99449

m-karasek
Level 1
Level 1

Hello,
From the new point of view, it looks that we need Patch 7. Does anybody know, what's wrong with the Patch 6, which has been found as not enough to repair the vulnerability? When we have P6 everywhere, are our ISE close to be safe, with just some minor problem, or it is the same vulnerable state, like before i patched everything from 4 to 6 ?