cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.

Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2

Vulnerabilities

Page 1 of 8
CVE-2025-20281P1CRITICALCVSS 10.0KEVPoCv3.3.0v3.3 Patch 2+7 more2025-06-25
CVE-2025-20281 [CRITICAL] CWE-74 CVE-2025-20281: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, rem A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An att
nvd
CVE-2025-20337P1CRITICALCVSS 10.0KEVv3.3.0v3.3 Patch 2+7 more2025-07-16
CVE-2025-20337 [CRITICAL] CWE-74 CVE-2025-20337: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, rem A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An att
nvd
CVE-2025-20282P1CRITICALCVSS 10.0ExploitedPoCv3.4.0v3.4 Patch 12025-06-25
CVE-2025-20282 [CRITICAL] CWE-269 CVE-2025-20282: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, re A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in
nvd
CVE-2023-20085P2MEDIUMCVSS 6.1Exploitedv3.2.02023-03-01
CVE-2023-20085 [MEDIUM] CWE-79 CVE-2023-20085: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-b
nvd
CVE-2026-20029P2MEDIUMCVSS 4.9Exploitedv3.1.0v3.1.0 p1+29 more2026-01-07
CVE-2026-20029 [MEDIUM] CWE-611 CVE-2026-20029: A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is due to improper parsing of XML that is processed by the web-based management
nvd
CVE-2025-20124P2HIGHCVSS 7.2PoCv3.0.0v3.0.0 p1+29 more2025-02-05
CVE-2025-20124 [HIGH] CWE-502 CVE-2025-20124: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbi A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java
nvd
CVE-2025-20125P2HIGHCVSS 7.2PoCv3.0.0v3.0.0 p1+29 more2025-02-05
CVE-2025-20125 [HIGH] CWE-285 CVE-2025-20125: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vu
nvd
CVE-2026-20147P2CRITICALCVSS 9.9v3.1.0v3.1.0 p1+38 more2026-04-15
CVE-2026-20147 [CRITICAL] CWE-77 CVE-2026-20147: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to exec A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An
nvd
CVE-2026-20180P2CRITICALCVSS 9.9v3.1.0v3.1.0 p1+31 more2026-04-15
CVE-2026-20180 [CRITICAL] CWE-22 CVE-2026-20180: A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-suppli
nvd
CVE-2026-20186P2CRITICALCVSS 9.9v3.1.0v3.1.0 p1+29 more2026-04-15
CVE-2026-20186 [CRITICAL] CWE-77 CVE-2026-20186: A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-suppli
nvd
CVE-2022-20964P2HIGHCVSS 8.8v2.6.0v2.6.0 p1+30 more2023-01-20
CVE-2022-20964 [HIGH] CWE-78 CVE-2022-20964: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management interface. An attacker could exploit this
nvd
CVE-2025-20286P2CRITICALCVSS 9.8v3.1.0v3.1.0 p1+25 more2025-06-04
CVE-2025-20286 [CRITICAL] CWE-259 CVE-2025-20286: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted sys
nvd
CVE-2022-20733P2CRITICALCVSS 9.8vn/a2022-06-15
CVE-2022-20733 [CRITICAL] CWE-287 CVE-2022-20733: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthentic A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by usi
nvd
CVE-2025-20284P2HIGHCVSS 7.2v3.3.0v3.3 Patch 2+7 more2025-07-16
CVE-2025-20284 [HIGH] CWE-74 CVE-2025-20284: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API
nvd
CVE-2026-20181P2CRITICALCVSS 9.1v3.1.0v3.1.0 p1+42 more2026-06-17
CVE-2026-20181 [CRITICAL] CWE-22 CVE-2026-20181: A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute ar A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attack
cvelistv5nvd
CVE-2022-20956P2HIGHCVSS 8.8v3.1.0v3.1.0 p1+3 more2022-11-04
CVE-2022-20956 [HIGH] CWE-648 CVE-2022-20956: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sen
nvd
CVE-2022-20962P2HIGHCVSS 8.8v3.1.0v3.1.0 p1+1 more2022-11-04
CVE-2022-20962 [HIGH] CWE-37 CVE-2022-20962: A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could al A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with a
nvd
CVE-2023-20272P3HIGHCVSS 8.8v3.0.0v3.0.0 p1+10 more2023-11-21
CVE-2023-20272 [HIGH] CWE-424 CVE-2023-20272: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading a malicious file to the web interfa
nvd
CVE-2025-20283P3HIGHCVSS 7.2v3.3.0v3.3 Patch 2+7 more2025-07-16
CVE-2025-20283 [HIGH] CWE-74 CVE-2025-20283: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API
nvd
CVE-2021-1594P3HIGHCVSS 8.1vn/a2021-10-06
CVE-2021-1594 [HIGH] CWE-266 CVE-2021-1594: A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticat A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specific API endpoints. An attacker in a man-in-the-middle position could exploit this vulnerability b
nvd
Cisco Identity Services Engine Software vulnerabilities | cvebase