Betroffene Einrichtungen
🏥 Krankenhaus🏨 Fachklinik🏃 Rehaklinik🏡 Pflegeheim🔬 Labor🏢 Ambulantes Zentrum
Bereich
IT-Infrastruktur
Beschreibung
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Handlungsempfehlung
1 Betroffene Systeme identifizieren und isolieren
2. Patch bzw. Workaround des Herstellers einspielen und Systeme neu starten
3. Netzwerksegmentierung und Logging-Konfiguration prüfen
4. Meldepflicht gemäss NIS2/B3S/ISG prüfen
Regulatorische Einordnung
NIS2-Relevanz: ••• B3S: ••• ISG: ••ˆ Meldepflicht DE: ja
Quelle: CISA KEV
— Original-Meldung →