cbcvebase.
CVE-2022-20733
published 2022-06-15

CVE-2022-20733: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and…

PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.04%
60.1th percentile
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscoidentity_services_engine
ciscoidentity_services_engine

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector involves accessing exposed SAML metadata on the Cisco ISE login page to bypass authentication — monitor for unauthenticated requests to SAML metadata endpoints on ISE
  • Successful exploitation grants access to all roles without restrictions — alert on privilege escalation or unexpected admin-level access originating from unauthenticated or low-privilege sessions on Cisco ISE
  • Track Cisco internal bug ID CSCvz67073 for patch and version correlation in asset management and vulnerability scanning
  • ·No workarounds are available for this vulnerability — patching via Cisco software updates is the only remediation path
  • ·Vulnerability is exploitable by unauthenticated remote attackers, meaning no prior access or credentials are required — ISE instances exposed to untrusted networks are at highest risk

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.