A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE. This vulnerability is due to an incorrect implementation of role-based access control (RBAC). An attacker could exploit this vulnerability by crafting a specific HTTP request with administrative credentials. A successful exploit could allow the attacker to generate a certificate that is signed and trusted by the ISE CA with arbitrary attributes. The attacker could use this certificate to access other networks or assets that are protected by certificate authentication.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 21 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: cisco
Published: 2019-05-16T01:20:35.523827Z
Updated: 2024-11-21T19:24:02.653Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1851
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-04T18:28:42.913Z
 NVD
                        NVD
                    Status : Modified
Published: 2019-05-16T02:29:00.543
Modified: 2024-11-21T04:37:31.803
Link: CVE-2019-1851
 Redhat
                        Redhat
                    No data.