cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

156 known vulnerabilities affecting cisco/cisco_identity_services_engine_software.

Total CVEs
156
CISA KEV
2
actively exploited
Public exploits
4
Exploited in wild
5
Severity breakdown
CRITICAL9HIGH31MEDIUM114LOW2

Vulnerabilities

Page 7 of 8
CVE-2020-3157P4MEDIUMCVSS 5.4≥ unspecified, < n/a2020-03-04
CVE-2020-3157 [MEDIUM] CWE-79 CVE-2020-3157: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2022-20967P4MEDIUMCVSS 5.4v2.6.0v2.6.0 p1+31 more2023-01-20
CVE-2022-20967 [MEDIUM] CWE-79 CVE-2022-20967: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within th
nvd
CVE-2024-20466P4MEDIUMCVSS 4.9v2.7.0v2.7.0 p1+31 more2024-08-21
CVE-2024-20466 [MEDIUM] CWE-266 CVE-2024-20466: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrat
nvd
CVE-2019-1719P4MEDIUMCVSS 5.4v2.12019-04-18
CVE-2019-1719 [MEDIUM] CWE-79 CVE-2019-1719: A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based interface.
nvd
CVE-2019-12637P4MEDIUMCVSS 5.4≥ unspecified, < n/a2019-10-16
CVE-2019-12637 [MEDIUM] CWE-79 CVE-2019-12637: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the
nvd
CVE-2019-12638P4MEDIUMCVSS 5.4≥ unspecified, < n/a2019-10-16
CVE-2019-12638 [MEDIUM] CWE-79 CVE-2019-12638: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based man
nvd
CVE-2026-20193P4MEDIUMCVSS 4.3v3.3.0v3.3 Patch 2+19 more2026-05-06
CVE-2026-20193 [MEDIUM] CWE-862 CVE-2026-20193: A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, r A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An at
nvd
CVE-2020-3525P4MEDIUMCVSS 4.3vN/A2024-11-18
CVE-2020-3525 [MEDIUM] CWE-200 CVE-2020-3525: A vulnerability in the Admin portal of Cisco&nbsp;Identity Services Engine (ISE) could allow an auth A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin portal. An attacker with read or write
nvd
CVE-2025-20332P4MEDIUMCVSS 4.3v3.1.0v3.1.0 p1+21 more2025-08-06
CVE-2025-20332 [MEDIUM] CWE-863 CVE-2025-20332: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request t
nvd
CVE-2024-20479P4MEDIUMCVSS 4.8v2.7.0v2.7.0 p1+37 more2024-08-07
CVE-2024-20479 [MEDIUM] CWE-79 CVE-2024-20479: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerabilit
nvd
CVE-2024-20539P4MEDIUMCVSS 4.8v3.0.0v3.0.0 p1+26 more2024-11-06
CVE-2024-20539 [MEDIUM] CWE-79 CVE-2024-20539: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injec
nvd
CVE-2026-20047P4MEDIUMCVSS 4.8v3.1.0v3.1.0 p1+29 more2026-01-15
CVE-2026-20047 [MEDIUM] CWE-80 CVE-2026-20047: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Ci A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by th
nvd
CVE-2026-20076P4MEDIUMCVSS 4.8v3.1.0v3.1.0 p1+23 more2026-01-15
CVE-2026-20076 [MEDIUM] CWE-79 CVE-2026-20076: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affec
nvd
CVE-2020-3340P4MEDIUMCVSS 4.8vn/a2020-07-02
CVE-2020-3340 [MEDIUM] CWE-79 CVE-2020-3340: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input that is proce
nvd
CVE-2020-3149P4MEDIUMCVSS 4.8≥ unspecified, < 2.7.02020-02-05
CVE-2020-3149 [MEDIUM] CWE-79 CVE-2020-3149: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this
nvd
CVE-2020-3589P4MEDIUMCVSS 4.8vn/a2020-10-08
CVE-2020-3589 [MEDIUM] CWE-79 CVE-2020-3589: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validat
nvd
CVE-2020-26083P4MEDIUMCVSS 4.8vn/a2020-11-06
CVE-2020-26083 [MEDIUM] CWE-79 CVE-2020-26083: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validate user-s
nvd
CVE-2021-34759P4MEDIUMCVSS 4.8vn/a2021-09-02
CVE-2021-34759 [MEDIUM] CWE-79 CVE-2021-34759: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly vali
nvd
CVE-2021-1606P4MEDIUMCVSS 4.8vn/a2021-07-08
CVE-2021-1606 [MEDIUM] CWE-79 CVE-2021-1606: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2021-1605P4MEDIUMCVSS 4.8vn/a2021-07-08
CVE-2021-1605 [MEDIUM] CWE-79 CVE-2021-1605: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
Cisco Identity Services Engine Software vulnerabilities | cvebase