Cisco Identity Services Engine vulnerabilities
166 known vulnerabilities affecting cisco/identity_services_engine.
Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2
Vulnerabilities
Page 1 of 9
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 2.4.0v2.4.0+6 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2025-20281P1CRITICALCVSS 10.0KEVPoCv3.3.0v3.4.02025-06-25
CVE-2025-20281 [CRITICAL] CWE-74 CVE-2025-20281: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, rem
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.
This vulnerability is due to insufficient validation of user-supplied input. An att
nvd
CVE-2025-20337P1CRITICALCVSS 10.0KEVv3.3.0v3.4.02025-07-16
CVE-2025-20337 [CRITICAL] CWE-74 CVE-2025-20337: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, rem
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.
This vulnerability is due to insufficient validation of user-supplied input. An att
nvd
CVE-2025-20282P1CRITICALCVSS 10.0ExploitedPoCv3.4.02025-06-25
CVE-2025-20282 [CRITICAL] CWE-269 CVE-2025-20282: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, re
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.
This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in
nvd
CVE-2023-20085P2MEDIUMCVSS 6.1Exploitedv3.22023-03-01
CVE-2023-20085 [MEDIUM] CWE-79 CVE-2023-20085: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
This vulnerability is due to insufficient validation of user-supplied input by the web-b
nvd
CVE-2025-20124P2HIGHCVSS 7.2PoCfixed in 3.1v3.1.0+2 more2025-02-05
CVE-2025-20124 [HIGH] CWE-502 CVE-2025-20124: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbi
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.
This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java
nvd
CVE-2025-20125P2HIGHCVSS 7.2PoCfixed in 3.1v3.1.0+2 more2025-02-05
CVE-2025-20125 [HIGH] CWE-285 CVE-2025-20125: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.
This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vu
nvd
CVE-2026-20147P2CRITICALCVSS 9.9fixed in 3.1.0v3.1.0+40 more2026-04-15
CVE-2026-20147 [CRITICAL] CWE-77 CVE-2026-20147: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to exec
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient validation of user-supplied input. An
nvd
CVE-2026-20180P2CRITICALCVSS 9.9fixed in 3.2.0v3.2.0+19 more2026-04-15
CVE-2026-20180 [CRITICAL] CWE-22 CVE-2026-20180: A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials.
This vulnerability is due to insufficient validation of user-suppli
nvd
CVE-2026-20186P2CRITICALCVSS 9.9fixed in 3.2.0v3.2.0+19 more2026-04-15
CVE-2026-20186 [CRITICAL] CWE-77 CVE-2026-20186: A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacke
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials.
This vulnerability is due to insufficient validation of user-suppli
nvd
CVE-2022-20964P2HIGHCVSS 8.8fixed in 2.6.0v2.6.0+4 more2023-01-20
CVE-2022-20964 [HIGH] CWE-78 CVE-2022-20964: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system.
This vulnerability is due to improper validation of user input within requests as part of the web-based management interface. An attacker could exploit this
nvd
CVE-2017-6747P2CRITICALCVSS 9.8v1.3\(0.722\)v1.3\(0.876\)+16 more2017-08-07
CVE-2017-6747 [CRITICAL] CWE-287 CVE-2017-6747: A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenti
nvd
CVE-2025-20286P2CRITICALCVSS 9.8v3.1.0v3.2.0+2 more2025-06-04
CVE-2025-20286 [CRITICAL] CWE-259 CVE-2025-20286: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI)
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted sys
nvd
CVE-2022-20733P2CRITICALCVSS 9.8v3.12022-06-15
CVE-2022-20733 [CRITICAL] CWE-287 CVE-2022-20733: A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthentic
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by usi
nvd
CVE-2025-20284P2HIGHCVSS 7.2fixed in 3.3.0v3.3.0+1 more2025-07-16
CVE-2025-20284 [HIGH] CWE-74 CVE-2025-20284: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root.
This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API
nvd
CVE-2026-20181P2CRITICALCVSS 9.1fixed in 3.3.0v3.3.0+20 more2026-06-17
CVE-2026-20181 [CRITICAL] CWE-22 CVE-2026-20181: A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute ar
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient validation of user-supplied input. An attack
nvd
CVE-2022-20956P2HIGHCVSS 8.8v3.1v3.22022-11-04
CVE-2022-20956 [HIGH] CWE-648 CVE-2022-20956: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files.
This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sen
nvd
CVE-2022-20962P2HIGHCVSS 8.8v3.12022-11-04
CVE-2022-20962 [HIGH] CWE-37 CVE-2022-20962: A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could al
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device.
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with a
nvd
CVE-2023-20272P3HIGHCVSS 8.8v3.0.0v3.12023-11-21
CVE-2023-20272 [HIGH] CWE-424 CVE-2023-20272: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading a malicious file to the web interfa
nvd
CVE-2025-20283P3HIGHCVSS 7.2fixed in 3.3.0v3.3.0+1 more2025-07-16
CVE-2025-20283 [HIGH] CWE-74 CVE-2025-20283: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root.
This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API
nvd
1 / 9Next →