Skip to main content

Advisories address two critical vulnerabilities in Smart Licensing Utility and one medium vulnerability in Identity Service Engine

Summary

Advisories address two critical vulnerabilities in Smart Licensing Utility and one medium vulnerability in Identity Service Engine

Affected platforms

The following platforms are known to be affected:

Cisco ISE
Cisco Smart Software ManagerCisco Smart Licensing Utility

Note: Cisco has confirmed that these vulnerabilities do not affect the following Cisco products:

Threat details

Introduction

Cisco has released a security advisory relating to two critical severity vulnerabilities in Smart Licensing Utility. Cisco Smart License Utility (CSLU) is an application that enables customers to administer licenses and their associated Product Instances from their premises instead of having to directly connect their Smart Licensed enabled Product Instances to Cisco Smart Software Manager (CSSM).

Cisco has also released an advisory regarding a command injection vulnerability affecting Identity Services Engine. Identity Services Engine is a security policy management platform that provides secure network access to end users and devices.

Remediation advice

Affected organisations are encouraged to review the Cisco Security Advisories page and apply the relevant updates detailed in the advisories below. 

Remediation steps

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 6 September 2024 12:20 pm