cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.

Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2

Vulnerabilities

Page 2 of 8
CVE-2022-20822P3HIGHCVSS 8.1vn/a2022-10-26
CVE-2022-20822 [HIGH] CWE-22 CVE-2022-20822: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contai
nvd
CVE-2024-20417P3HIGHCVSS 8.1v2.7.0v2.7.0 p1+38 more2024-08-21
CVE-2024-20417 [HIGH] CWE-89 CVE-2024-20417: Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an auth Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected
nvd
CVE-2023-20175P3HIGHCVSS 8.8v2.6.0v2.6.0 p1+33 more2023-11-01
CVE-2023-20175 [HIGH] CWE-78 CVE-2023-20175: A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insuf
nvd
CVE-2024-20368P3HIGHCVSS 8.8v2.7.0v2.7.0 p1+33 more2024-04-03
CVE-2024-20368 [HIGH] CWE-352 CVE-2024-20368: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an a
nvd
CVE-2024-20486P3HIGHCVSS 8.8v2.7.0v2.7.0 p1+38 more2024-08-21
CVE-2024-20486 [HIGH] CWE-352 CVE-2024-20486: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an
nvd
CVE-2023-20243P3HIGHCVSS 8.6v3.1.0v3.1.0 p1+7 more2023-09-06
CVE-2023-20243 [HIGH] CWE-399 CVE-2023-20243: A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) cou A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could exploit this vulnerability by sending a
nvd
CVE-2025-20152P3HIGHCVSS 8.6v3.4.02025-05-21
CVE-2025-20152 [HIGH] CWE-125 CVE-2025-20152: A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) cou A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specif
nvd
CVE-2026-20190P3HIGHCVSS 7.5v3.4.0v3.4 Patch 1+7 more2026-06-17
CVE-2026-20190 [HIGH] CWE-285 CVE-2026-20190: A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sen A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could
cvelistv5nvd
CVE-2024-20528P3HIGHCVSS 7.2v3.1.0v3.1.0 p1+19 more2024-11-06
CVE-2024-20528 [HIGH] CWE-22 CVE-2024-20528: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload file A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-supplied parameters in A
nvd
CVE-2025-20130P3HIGHCVSS 7.2v3.0.0v3.0.0 p1+28 more2025-06-04
CVE-2025-20130 [HIGH] CWE-284 CVE-2025-20130: A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerabili
nvd
CVE-2022-20961P3HIGHCVSS 8.8v2.6.0v2.6.0 p1+26 more2022-11-04
CVE-2022-20961 [HIGH] CWE-352 CVE-2022-20961: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an a
nvd
CVE-2024-20296P3HIGHCVSS 7.2v2.7.0v2.7.0 p1+36 more2024-07-17
CVE-2024-20296 [HIGH] CWE-434 CVE-2024-20296: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device. This vulnerability is due to improper validatio
nvd
CVE-2023-20196P3HIGHCVSS 7.2v2.6.0v2.6.0 p1+37 more2023-11-01
CVE-2023-20196 [HIGH] CWE-434 CVE-2023-20196: Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary f Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management inter
nvd
CVE-2023-20195P3HIGHCVSS 7.2v2.6.0v2.6.0 p1+37 more2023-11-01
CVE-2023-20195 [HIGH] CWE-434 CVE-2023-20195: Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary f Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management inter
nvd
CVE-2023-20163P3HIGHCVSS 7.2vn/a2023-05-18
CVE-2023-20163 [HIGH] CWE-78 CVE-2023-20163: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,
nvd
CVE-2023-20164P3HIGHCVSS 7.2vn/a2023-05-18
CVE-2023-20164 [HIGH] CWE-78 CVE-2023-20164: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,
nvd
CVE-2025-20343P3HIGHCVSS 7.5v3.4.0v3.4 Patch 1+2 more2025-11-05
CVE-2025-20343 [HIGH] CWE-697 CVE-2025-20343: A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejec
nvd
CVE-2022-20756P3HIGHCVSS 7.5vn/a2022-04-06
CVE-2022-20756 [HIGH] CWE-399 CVE-2022-20756: A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthe A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by attempting to authenticate to a network
nvd
CVE-2020-3467P3HIGHCVSS 7.7vn/a2020-10-08
CVE-2020-3467 [HIGH] CWE-863 CVE-2020-3467: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. The vulnerability is due to improper enforcement of role-based access control (RBAC) within the web-based management interface. An attacker could exploit th
nvd
CVE-2018-15459P3HIGHCVSS 7.2vn/a2019-01-23
CVE-2018-15459 [HIGH] CWE-284 CVE-2018-15459: A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could al A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on certain pages in the web interface. An attacker could exploit this vulnerability by authenticating to the device
nvd
Cisco Identity Services Engine Software vulnerabilities | cvebase