cbcvebase.

Cisco Identity Services Engine vulnerabilities

166 known vulnerabilities affecting cisco/identity_services_engine.

Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2

Vulnerabilities

Page 2 of 9
CVE-2021-1594P3HIGHCVSS 8.1≥ 2.4.0, < 2.6.0v2.4\(0.902\)+7 more2021-10-06
CVE-2021-1594 [HIGH] CWE-266 CVE-2021-1594: A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticat A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specific API endpoints. An attacker in a man-in-the-middle position could exploit this vulnerability b
nvd
CVE-2018-0213P3HIGHCVSS 8.8v2.1\(0.904\)2018-03-08
CVE-2018-0213 [HIGH] CWE-264 CVE-2018-0213: A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A success
nvd
CVE-2022-20822P3HIGHCVSS 8.1v3.1v3.22022-10-26
CVE-2022-20822 [HIGH] CWE-22 CVE-2022-20822: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request that contai
nvd
CVE-2024-20417P3HIGHCVSS 8.1≤ 3.1v3.1.0+2 more2024-08-21
CVE-2024-20417 [HIGH] CWE-89 CVE-2024-20417: Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an auth Multiple vulnerabilities in the REST API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct blind SQL injection attacks. These vulnerabilities are due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit these vulnerabilities by sending crafted input to an affected
nvd
CVE-2023-20175P3HIGHCVSS 8.8v2.6.0v2.7.0+3 more2023-11-01
CVE-2023-20175 [HIGH] CWE-78 CVE-2023-20175: A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insuf
nvd
CVE-2024-20368P3HIGHCVSS 8.8≥ 2.7.0, < 3.1.0v3.1.0+2 more2024-04-03
CVE-2024-20368 [HIGH] CWE-352 CVE-2024-20368: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an a
nvd
CVE-2024-20486P3HIGHCVSS 8.8≥ 2.7.0, < 3.1v3.1.0+2 more2024-08-21
CVE-2024-20486 [HIGH] CWE-352 CVE-2024-20486: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an
nvd
CVE-2023-20243P3HIGHCVSS 8.6v3.1v3.22023-09-06
CVE-2023-20243 [HIGH] CWE-399 CVE-2023-20243: A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) cou A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could exploit this vulnerability by sending a
nvd
CVE-2025-20152P3HIGHCVSS 8.6v3.4.02025-05-21
CVE-2025-20152 [HIGH] CWE-125 CVE-2025-20152: A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) cou A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specif
nvd
CVE-2026-20190P3HIGHCVSS 7.5v3.4.0v3.4.0-patch1+7 more2026-06-17
CVE-2026-20190 [HIGH] CWE-285 CVE-2026-20190: A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sen A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could
nvd
CVE-2024-20528P3HIGHCVSS 7.2≥ 3.0.0, < 3.1.0v3.1.0+2 more2024-11-06
CVE-2024-20528 [HIGH] CWE-22 CVE-2024-20528: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload file A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin credentials. This vulnerability is due to insufficient validation of user-supplied parameters in A
nvd
CVE-2025-20130P3HIGHCVSS 7.2fixed in 3.1.0v3.1.0+2 more2025-06-04
CVE-2025-20130 [HIGH] CWE-284 CVE-2025-20130: A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Co A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerabili
nvd
CVE-2022-20961P3HIGHCVSS 8.8fixed in 2.6.0v2.6.0+3 more2022-11-04
CVE-2022-20961 [HIGH] CWE-352 CVE-2022-20961: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an a
nvd
CVE-2024-20296P3HIGHCVSS 7.2≥ 3.0.0, < 3.1v3.1.0+2 more2024-07-17
CVE-2024-20296 [HIGH] CWE-434 CVE-2024-20296: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device. This vulnerability is due to improper validatio
nvd
CVE-2018-0277P3HIGHCVSS 8.6v2.0\(0.306\)v2.0\(1.130\)+2 more2018-05-17
CVE-2018-0277 [HIGH] CWE-295 CVE-2018-0277: A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certifi A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected
nvd
CVE-2023-20196P3HIGHCVSS 7.2v2.7.0v3.0.0+2 more2023-11-01
CVE-2023-20196 [HIGH] CWE-434 CVE-2023-20196: Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary f Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management inter
nvd
CVE-2023-20195P3HIGHCVSS 7.2v2.7.0v3.0.0+2 more2023-11-01
CVE-2023-20195 [HIGH] CWE-434 CVE-2023-20195: Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary f Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management inter
nvd
CVE-2023-20163P3HIGHCVSS 7.2≤ 2.7v3.0.0+2 more2023-05-18
CVE-2023-20163 [HIGH] CWE-78 CVE-2023-20163: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,
nvd
CVE-2023-20164P3HIGHCVSS 7.2≤ 2.7v3.0.0+2 more2023-05-18
CVE-2023-20164 [HIGH] CWE-78 CVE-2023-20164: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,
nvd
CVE-2025-20343P3HIGHCVSS 7.5v3.4.02025-11-05
CVE-2025-20343 [HIGH] CWE-697 CVE-2025-20343: A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejec
nvd
Cisco Identity Services Engine vulnerabilities | cvebase