cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.

Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2

Vulnerabilities

Page 3 of 8
CVE-2024-20531P3MEDIUMCVSS 6.5v3.0.0v3.0.0 p1+29 more2024-11-06
CVE-2024-20531 [MEDIUM] CWE-611 CVE-2024-20531: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitr A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerab
nvd
CVE-2022-20966P3MEDIUMCVSS 5.4v2.6.0v2.6.0 p1+31 more2023-01-20
CVE-2022-20966 [MEDIUM] CWE-79 CVE-2022-20966: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within th
nvd
CVE-2026-20148P3MEDIUMCVSS 4.9v3.1.0v3.1.0 p1+36 more2026-04-15
CVE-2026-20148 [MEDIUM] CWE-22 CVE-2026-20148: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perf A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An
nvd
CVE-2023-20077P3MEDIUMCVSS 6.5vn/a2023-05-18
CVE-2023-20077 [MEDIUM] CWE-37 CVE-2023-20077: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted H
nvd
CVE-2023-20087P3MEDIUMCVSS 6.5vn/a2023-05-18
CVE-2023-20087 [MEDIUM] CWE-37 CVE-2023-20087: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted H
nvd
CVE-2019-1718P3HIGHCVSS 7.5v2.1(0.907)2019-04-17
CVE-2019-1718 [HIGH] CWE-399 CVE-2019-1718: A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthen A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of Secure Sockets Layer (SSL) renegotiation requests. An attacker could exploit this vulnerability by sendi
nvd
CVE-2023-20122P3HIGHCVSS 7.8vn/a2023-04-05
CVE-2023-20122 [HIGH] CWE-77 CVE-2023-20122: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabilit
nvd
CVE-2019-1942P3MEDIUMCVSS 6.5≥ unspecified, < 2.6.02019-07-17
CVE-2019-1942 [MEDIUM] CWE-89 CVE-2019-1942: A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could a A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending c
nvd
CVE-2024-20537P3MEDIUMCVSS 6.5v3.0.0v3.0.0 p1+27 more2024-11-06
CVE-2024-20537 [MEDIUM] CWE-863 CVE-2024-20537: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafte
nvd
CVE-2021-40123P3MEDIUMCVSS 6.5vn/a2021-10-21
CVE-2021-40123 [MEDIUM] CWE-266 CVE-2021-40123: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incorrect permissions settings on an affected device. An attacker could exploit this vulnerabilit
nvd
CVE-2023-20171P3MEDIUMCVSS 6.5vn/a2023-05-18
CVE-2023-20171 [MEDIUM] CWE-602 CVE-2023-20171: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this
nvd
CVE-2026-20146P3MEDIUMCVSS 5.5v3.1.0v3.1.0 p1+40 more2026-07-15
CVE-2026-20146 [MEDIUM] CWE-22 CVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (IS A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.
nvd
CVE-2024-20515P3MEDIUMCVSS 6.5v3.0.0v3.0.0 p1+29 more2024-10-02
CVE-2024-20515 [MEDIUM] CWE-311 CVE-2024-20515: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator priv
nvd
CVE-2025-20264P3MEDIUMCVSS 6.4v3.0.0v3.0.0 p1+33 more2025-06-25
CVE-2025-20264 [MEDIUM] CWE-285 CVE-2025-20264: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an exte
nvd
CVE-2019-15255P3MEDIUMCVSS 6.5≥ unspecified, < n/a2020-01-26
CVE-2019-15255 [MEDIUM] CWE-284 CVE-2019-15255: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vuln
nvd
CVE-2025-20303P3MEDIUMCVSS 5.4v3.1.0v3.1.0 p1+29 more2025-11-05
CVE-2025-20303 [MEDIUM] CWE-79 CVE-2025-20303: Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An at
nvd
CVE-2023-20111P3MEDIUMCVSS 6.5v2.6.0v2.6.0 p1+33 more2023-08-16
CVE-2023-20111 [MEDIUM] CWE-497 CVE-2023-20111: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit this vulnerability by logging in to
nvd
CVE-2026-20136P3MEDIUMCVSS 6.0v3.1.0v3.1.0 p1+39 more2026-04-15
CVE-2026-20136 [MEDIUM] CWE-116 CVE-2026-20136: A vulnerability in the&nbsp;CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identi A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This vulnerability is due to insufficient validatio
nvd
CVE-2019-1851P3MEDIUMCVSS 6.8≥ unspecified, < n/a2019-05-16
CVE-2019-1851 [MEDIUM] CWE-285 CVE-2019-1851: A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (IS A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE. This vulnerability is due to an incorrect implementation of role-based access control (RBAC). An attac
nvd
CVE-2018-0187P3MEDIUMCVSS 6.5vn/a2019-01-23
CVE-2018-0187 [MEDIUM] CWE-200 CVE-2018-0187: A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authentic A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information. An attacker could exploit this vulnerability by logging into the web interface on a vulnerab
nvd