cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
734
Views
0
Helpful
6
Replies

ISE: CVE-2023-28531: Vulnerabilities in openssh 8.0p1

jds5
Level 1
Level 1

 

Hello,

Do you know what the exact impact of this vulnerability is on an ISE SNS-3655-K9 in version 3.3 P3?

BR,

José

6 Replies 6

It's a discovered vulnerability on the Linux based OS which ISE uses as well and it could cause a leakage of some sensitive information or denial of service as per this NetApp link provided by nist.gov:

CVE-2023-28531 OpenSSH Vulnerability in NetApp Products | NetApp Product Security

NVD - CVE-2023-28531 (nist.gov)

jds5
Level 1
Level 1

Does version 3.4 fix this vulnerability?

jds5
Level 1
Level 1

Hello, 

Does someone have this information? Thank you,

BR,

Looking at the resolved bugs list in ISE 3.4 it does not seem to include it:

Release Notes for Cisco Identity Services Engine, Release 3.4 - Cisco

Kyle Stewart
Level 1
Level 1

I would be nice if this was included in P4 coming sometime this month (which fixes CVE-2024-20469). 

Kyle Stewart
Level 1
Level 1

Look here. This doesn't affect ISE at all. Change the criteria to Not Affected and you'll see that confirmation. I'm sure this has to do with using customized versions of OpenSSH but vulnerability scanners only look at the version # (at least some of them).

https://sec.cloudapps.cisco.com/security/center/cvr?cveIdList=CVE-2023-28531#~cve