SecBoard
Zurück zur CVE-Übersicht

CVE-2026-20247

HIGH(7.5)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Risk Signal Score29/100 — MITTEL
  • CVSS 7.5 — Hoch
  • Weniger als 24 Stunden alt

Erwähnungen (letzte 60 Tage)

Artikel

Beschreibung

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.

Erkennung & Indikatoren

Ausnutzung

In den geprüften Quellen nicht genannt

Threat-Hunting-Queries

Detects attempts to exploit SQL injection vulnerabilities in Cisco ISE by monitoring for unusual or malformed requests that indicate improper validation of user-supplied input. This query is generic and may require tuning to reduce false positives.

Sentinel/Defender KQL

let KnownISEEndpoints = dynamic(["/admin", "/guest", "/portal"]);
SecurityEvent
| where EventID == 4625 or EventID == 4624 // Failed/Successful logon attempts, adjust based on ISE logging
| where IpAddress !in ("127.0.0.1", "::1") // Exclude localhost
| extend RequestUri = tostring(parse_json(EventData).RequestUri)
| where RequestUri has_any (KnownISEEndpoints)
| where RequestUri matches regex @"[\s'"`\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19\x1a\x1b\x1c\x1d\x1e\x1f\x20\x21\x22\x23\x24\x25\x26\x27\x28\x29\x2a\x2b\x2c\x2d\x2e\x2f\x30\x31\x32\x33\x34\x35\x36\x37\x38\x39\x3a\x3b\x3c\x3d\x3e\x3f\x40\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5a\x5b\x5c\x5d\x5e\x5f\x60\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x7b\x7c\x7d\x7e\x7f\x80\x81\x82\x83\x84\x85\x86\x87\x88\x89\x8a\x8b\x8c\x8d\x8e\x8f\x90\x91\x92\x93\x94\x95\x96\x97\x98\x99\x9a\x9b\x9c\x9d\x9e\x9f\xa0\xa1\xa2\xa3\xa4\xa5\xa6\xa7\xa8\xa9\xaa\xab\xac\xad\xae\xaf\xb0\xb1\xb2\xb3\xb4\xb5\xb6\xb7\xb8\xb9\xba\xbb\xbc\xbd\xbe\xbf\xc0\xc1\xc2\xc3\xc4\xc5\xc6\xc7\xc8\xc9\xca\xcb\xcc\xcd\xce\xcf\xd0\xd1\xd2\xd3\xd4\xd5\xd6\xd7\xd8\xd9\xda\xdb\xdc\xdd\xde\xdf\xe0\xe1\xe2\xe3\xe4\xe5\xe6\xe7\xe8\xe9\xea\xeb\xec\xed\xee\xef\xf0\xf1\xf2\xf3\xf4\xf5\xf6\xf7\xf8\xf9\xfa\xfb\xfc\xfd\xfe\xff]" or RequestUri contains "SELECT" or RequestUri contains "UNION" or RequestUri contains "OR 1=1" or RequestUri contains "--" or RequestUri contains "/*" or RequestUri contains "xp_cmdshell" or RequestUri contains "exec(" or RequestUri contains "information_schema" or RequestUri contains "pg_sleep(")

Splunk SPL

index=* (sourcetype=cisco:ise OR sourcetype=web_access_log) (uri_path="/admin*" OR uri_path="/guest*" OR uri_path="/portal*") (uri_query=* OR body=*)
| regex _raw="(?i)(['\"]|\b(SELECT|UNION|OR\s+1=1|--|/\*|xp_cmdshell|exec\(|information_schema|pg_sleep\())"
| table _time, host, src_ip, uri_path, uri_query, body, _raw

Sigma

title: Cisco ISE SQL Injection Attempt
id: 00000000-0000-0000-0000-000000000001
status: experimental
description: Detects potential SQL injection attempts against Cisco ISE by looking for suspicious characters or keywords in web requests.
references:
  - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947
logsource:
  category: webserver
  product: cisco_ise
detection:
  selection:
    url|contains:
      - "/admin"
      - "/guest"
      - "/portal"
    query|contains:
      - "'"
      - "\""
      - "SELECT"
      - "UNION"
      - "OR 1=1"
      - "--"
      - "/*"
      - "xp_cmdshell"
      - "exec("
      - "information_schema"
      - "pg_sleep("
  condition: selection
level: high

Elastic ES|QL

from logs-cisco.ise-* or logs-webserver-*
| where url.path : ("/admin*", "/guest*", "/portal*")
| where url.query : ("'", "\"", "SELECT", "UNION", "OR 1=1", "--", "/*", "xp_cmdshell", "exec(", "information_schema", "pg_sleep(")
| select @timestamp, host.name, source.ip, url.path, url.query, http.request.body.content

SecBoard-generated · behavioral · requires customizationVon SecBoard erzeugt und nicht in einer Zielumgebung validiert. Vor dem Einsatz an die eigene Protokollierung anpassen.

Referenzen