Cisco Identity Services Engine Software vulnerabilities
156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.
Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2
Vulnerabilities
Page 5 of 8
CVE-2024-20332P4MEDIUMCVSS 5.5v3.2.0v3.2.0 p1+4 more2024-04-03
CVE-2024-20332 [MEDIUM] CWE-918 CVE-2024-20332: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability b
nvd
CVE-2022-20965P4MEDIUMCVSS 5.4v2.6.0v2.6.0 p1+31 more2023-01-20
CVE-2022-20965 [MEDIUM] CWE-648 CVE-2022-20965: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface.
This vulnerability is due to improper access control on a feature within the web-based management interface of the affected system. An attacker coul
nvd
CVE-2020-27122P4MEDIUMCVSS 6.7vn/a2020-11-06
CVE-2020-27122 [MEDIUM] CWE-266 CVE-2020-27122: A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE
A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator account on an affected device. The vulnerability is due to incorrect privil
nvd
CVE-2018-15425P4MEDIUMCVSS 4.7vn/a2018-10-05
CVE-2018-15425 [MEDIUM] CWE-20 CVE-2018-15425: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
nvd
CVE-2023-20121P4MEDIUMCVSS 6.7vn/a2023-04-05
CVE-2023-20121 [MEDIUM] CWE-77 CVE-2023-20121: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabil
nvd
CVE-2024-20530P4MEDIUMCVSS 6.1v3.0.0v3.0.0 p1+29 more2024-11-06
CVE-2024-20530 [MEDIUM] CWE-79 CVE-2024-20530: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2024-20525P4MEDIUMCVSS 6.1v3.0.0v3.0.0 p1+29 more2024-11-06
CVE-2024-20525 [MEDIUM] CWE-79 CVE-2024-20525: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2022-20937P4MEDIUMCVSS 5.3v2.6.0v2.6.0 p1+26 more2022-11-04
CVE-2022-20937 [MEDIUM] CWE-410 CVE-2022-20937: A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) S
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device.
This vulnerability is due to insufficient management of system resources. An attacker could exploit this vulnerability by taking action
nvd
CVE-2018-15424P4MEDIUMCVSS 4.7vn/a2018-10-05
CVE-2018-15424 [MEDIUM] CWE-20 CVE-2018-15424: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
nvd
CVE-2023-20173P4MEDIUMCVSS 4.9vn/a2023-05-18
CVE-2023-20173 [MEDIUM] CWE-611 CVE-2023-20173: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the
nvd
CVE-2019-1736P4MEDIUMCVSS 6.6vn/a2020-09-23
CVE-2019-1736 [MEDIUM] CWE-347 CVE-2019-1736: A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated,
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. A
nvd
CVE-2020-3156P4MEDIUMCVSS 6.1≥ unspecified, < n/a2020-02-19
CVE-2020-3156 [MEDIUM] CWE-79 CVE-2020-3156: A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenti
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of endpoint data stored in logs used by the web-based interface. An attacker could exploit this vulnerability by sending malicious endpoint
nvd
CVE-2024-20538P4MEDIUMCVSS 6.1v3.0.0v3.0.0 p1+28 more2024-11-06
CVE-2024-20538 [MEDIUM] CWE-79 CVE-2024-20538: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, r
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface.
This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2025-20289P4MEDIUMCVSS 5.4v3.1.0v3.1.0 p1+28 more2025-11-05
CVE-2025-20289 [MEDIUM] CWE-79 CVE-2025-20289: Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An at
nvd
CVE-2025-20304P4MEDIUMCVSS 5.4v3.1.0v3.1.0 p1+29 more2025-11-05
CVE-2025-20304 [MEDIUM] CWE-79 CVE-2025-20304: Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An at
nvd
CVE-2023-20174P4MEDIUMCVSS 4.9vn/a2023-05-18
CVE-2023-20174 [MEDIUM] CWE-611 CVE-2023-20174: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the
nvd
CVE-2023-20194P4MEDIUMCVSS 4.9v2.6.0v2.6.0 p1+37 more2023-09-07
CVE-2023-20194 [MEDIUM] CWE-268 CVE-2023-20194: A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read ar
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the
nvd
CVE-2023-20167P4MEDIUMCVSS 4.9vn/a2023-05-18
CVE-2023-20167 [MEDIUM] CWE-24 CVE-2023-20167: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For mo
nvd
CVE-2023-20172P4MEDIUMCVSS 4.9vn/a2023-05-18
CVE-2023-20172 [MEDIUM] CWE-602 CVE-2023-20172: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this
nvd
CVE-2018-15463P4MEDIUMCVSS 6.1vn/a2019-01-15
CVE-2018-15463 [MEDIUM] CWE-79 CVE-2018-15463: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management
nvd