cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.

Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2

Vulnerabilities

Page 4 of 8
CVE-2021-1412P3MEDIUMCVSS 6.5vn/a2021-02-17
CVE-2021-1412 [MEDIUM] CWE-266 CVE-2021-1412: Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit
nvd
CVE-2022-20782P3MEDIUMCVSS 6.5vn/a2022-04-06
CVE-2022-20782 [MEDIUM] CWE-266 CVE-2022-20782: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrato
nvd
CVE-2024-20469P3MEDIUMCVSS 6.7v3.2.0v3.2.0 p1+9 more2024-09-04
CVE-2024-20469 [MEDIUM] CWE-78 CVE-2024-20469: A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an auth A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on an affected device. This vulnerab
nvd
CVE-2022-20819P3MEDIUMCVSS 6.5vn/a2022-06-15
CVE-2022-20819 [MEDIUM] CWE-266 CVE-2022-20819: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive data are not properly enforced. An attacker with read-only privileges for t
nvd
CVE-2024-20532P3MEDIUMCVSS 5.5v3.0.0v3.0.0 p1+29 more2024-11-06
CVE-2024-20532 [MEDIUM] CWE-22 CVE-2024-20532: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2024-20529P3MEDIUMCVSS 5.5v3.1.0v3.1.0 p1+19 more2024-11-06
CVE-2024-20529 [MEDIUM] CWE-22 CVE-2024-20529: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2024-20527P3MEDIUMCVSS 5.5v3.0.0v3.0.0 p1+29 more2024-11-06
CVE-2024-20527 [MEDIUM] CWE-22 CVE-2024-20527: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2026-20195P3MEDIUMCVSS 5.3v3.3.0v3.3 Patch 2+19 more2026-05-06
CVE-2026-20195 [MEDIUM] CWE-204 CVE-2026-20195: A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted
nvd
CVE-2023-20021P3MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20021 [MEDIUM] CWE-78 CVE-2023-20021: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20022P3MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20022 [MEDIUM] CWE-78 CVE-2023-20022: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20023P3MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20023 [MEDIUM] CWE-78 CVE-2023-20023: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20152P3MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20152 [MEDIUM] CWE-77 CVE-2023-20152: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20153P3MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20153 [MEDIUM] CWE-77 CVE-2023-20153: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20170P4MEDIUMCVSS 6.7vN/A2023-11-01
CVE-2023-20170 [MEDIUM] CWE-77 CVE-2023-20170: A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to insuffici
nvd
CVE-2023-20166P4MEDIUMCVSS 6.7vn/a2023-05-18
CVE-2023-20166 [MEDIUM] CWE-24 CVE-2023-20166: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For mo
nvd
CVE-2023-20193P4MEDIUMCVSS 6.7v2.6.0v2.6.0 p1+37 more2023-09-07
CVE-2023-20193 [MEDIUM] CWE-78 CVE-2023-20193: A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, loca A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulner
nvd
CVE-2023-20030P3MEDIUMCVSS 6.0vn/a2023-04-05
CVE-2023-20030 [MEDIUM] CWE-611 CVE-2023-20030: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself. This vulnerab
nvd
CVE-2021-34706P4MEDIUMCVSS 5.4vn/a2021-10-06
CVE-2021-34706 [MEDIUM] CWE-611 CVE-2021-34706: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing
nvd
CVE-2025-20131P4MEDIUMCVSS 4.9v3.1.0v3.1.0 p1+19 more2025-08-20
CVE-2025-20131 [MEDIUM] CWE-284 CVE-2025-20131: A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, rem A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload using the Cis
nvd
CVE-2019-15282P4MEDIUMCVSS 5.3≥ unspecified, < n/a2019-10-16
CVE-2019-15282 [MEDIUM] CWE-306 CVE-2019-15282: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability is due an issue in the authentication logic of the web-based management interface. An attacker could exploit this vulnerability by
nvd
Cisco Identity Services Engine Software vulnerabilities | cvebase