Cisco patches critical security issues, so update now Two critical-severity flaws recently addressed in Cisco Identity Services Engine.
Since the flaws can be abused to run arbitrary commands and steal sensitive information, Cisco urged its users to apply the fixes as soon as possible.
By sending a custom serialized Java object to an affected Cisco ISE API, an attacker could execute arbitrary commands and elevate privileges.
Cisco has released patches for two critical-severity vulnerabilities plaguing its Identity Services Engine (ISE) solution.
Cisco said that threat actors would still need to be authenticated, and with a read-only admin account, at that.