Sunday, 15 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Cisco identifies vulnerability in ISE network access control devices
Global Market

Cisco identifies vulnerability in ISE network access control devices

Last updated: January 9, 2026 5:59 am
Published January 9, 2026
Share
Cisco
SHARE

Johannes Ullrich, dean of analysis on the SANS Institute, stated, “Most probably, that is an XML Exterior Entity vulnerability.” Exterior entities, he defined, are an XML function that instructs the parser to both learn native recordsdata or entry exterior URLs. On this case, an attacker might embed an exterior entity within the license file, instructing the XML parser to learn a confidential file and embrace it within the response. It is a frequent vulnerability in XML parsers, he stated, sometimes mitigated by disabling exterior entity parsing.

An attacker would have the ability to acquire learn entry to confidential recordsdata like configuration recordsdata, he added, and probably person credentials. Ullrich additionally stated an ISE administrator could have entry to numerous the data, however they need to not have entry to person credentials.

The Cisco advisory says an attacker might exploit this vulnerability by importing a malicious file to the appliance: “A profitable exploit might permit the attacker to learn arbitrary recordsdata from the underlying working system that would embrace delicate information that ought to in any other case be inaccessible even to directors. To take advantage of this vulnerability, the attacker should have legitimate administrative credentials.”

Cisco stated proof-of-concept exploit code is out there for this vulnerability, however up to now the corporate isn’t conscious of any malicious use of the outlet. 

Today, admin credentials aren’t onerous to get, Harrington famous. The “soiled secret that few individuals wish to discuss is throughout IT and safety operations there are such a lot of techniques which are left with default credentials.” That’s notably frequent, he stated, with gadgets behind a firewall, akin to community entry management servers, as a result of admins suppose as a result of they’re contained in the community they’ll’t be touched by exterior hackers. However plenty of credentials might be scooped up in compromises of functions the place Cisco admins may need saved passwords.

See also  AMD data center chips vulnerable to revealing data through ‘BadRAM’ attack

Associated content material: Cisco warns of three critical ISE vulnerabilities

Source link

TAGGED: access, Cisco, control, devices, identifies, ISE, Network, vulnerability
Share This Article
Twitter Email Copy Link Print
Previous Article Marvell to acquire XConn, boosting AI data centre connectivity Marvell to acquire XConn, boosting AI data centre connectivity
Next Article Schneider Electric appoints Matthew Baynes VP of data centre division Schneider Electric appoints Matthew Baynes VP of data centre division
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Why Financial Institutions Need an Agile Cloud Strategy

Information facilities type the muse of our digital world, but many stay anchored in outdated…

July 11, 2025

Qualcomm Enters Data Center AI Chip Market

Qualcomm has unveiled two new AI accelerator chips for the booming knowledge heart market, taking…

October 27, 2025

Voze Raises $12M in Series A Funding

Voze, a Salt Lake Metropolis, UT-based supplier of a gross sales resolution devoted to empowering…

October 28, 2024

BeamXR Raises £532K in Funding

BeamXR, a Newcastle Upon Tyne, UK-based artistic tech firm, raised £532k in funding. The spherical…

December 13, 2024

Sponge-like carbon nanotube thermoelectric generator easily molds to complex shapes and powers sensors

Schematic illustration exhibiting the fabrication technique of the CNT/BST foam with numerous shapes. Results of…

April 30, 2025

You Might Also Like

Big data technology and data science illustration. Data flow concept. Querying, analysing, visualizing complex information. Neural network for artificial intelligence. Data mining. Business analytics.
Global Market

Nvidia claims 10x cost savings with open-source inference models

By saad
artificial intelligence AI hands conceptual
Global Market

Arista laments ‘horrendous’ memory situation

By saad
Auckland / New Zealand - November 7 2019: View of Microsoft office building
Global Market

FTC digs deeper into Microsoft’s bundling and licensing practices

By saad
The internet’s next upgrade should be cleaner
Global Market

The internet’s next upgrade should be cleaner

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.