CVE-2022-20733
published 2022-06-15CVE-2022-20733: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.04%
60.1th percentile
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector involves accessing exposed SAML metadata on the Cisco ISE login page to bypass authentication — monitor for unauthenticated requests to SAML metadata endpoints on ISE ↗
- →Successful exploitation grants access to all roles without restrictions — alert on privilege escalation or unexpected admin-level access originating from unauthenticated or low-privilege sessions on Cisco ISE ↗
- →Track Cisco internal bug ID CSCvz67073 for patch and version correlation in asset management and vulnerability scanning ↗
- ·No workarounds are available for this vulnerability — patching via Cisco software updates is the only remediation path ↗
- ·Vulnerability is exploitable by unauthenticated remote attackers, meaning no prior access or credentials are required — ISE instances exposed to untrusted networks are at highest risk ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Authentication Bypass Vulnerability
vendor_cisco·2022-06-15·CVSS 5.3
CVE-2022-20733 [MEDIUM] CWE-287 Cisco Identity Services Engine Authentication Bypass Vulnerability
Cisco Identity Services Engine Authentication Bypass Vulnerability
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions.
This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security
Cisco
Cisco Identity Services Engine Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.1
CVE-2022-20733 Cisco Identity Services Engine Authentication Bypass Vulnerability
CVE-2022-20733: Cisco Identity Services Engine Authentication Bypass Vulnerability
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-287, CWE-287
Bug IDs: CSCvz67073
GHSA
GHSA-gqhw-x424-g962: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credential
ghsa_unreviewed·2022-06-16
CVE-2022-20733 [CRITICAL] CWE-287 GHSA-gqhw-x424-g962: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credential
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-15
Published