cbcvebase.

Cisco Identity Services Engine vulnerabilities

166 known vulnerabilities affecting cisco/identity_services_engine.

Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2

Vulnerabilities

Page 3 of 9
CVE-2022-20756P3HIGHCVSS 7.5v2.2.0v2.4.0+5 more2022-04-06
CVE-2022-20756 [HIGH] CWE-399 CVE-2022-20756: A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthe A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by attempting to authenticate to a network
nvd
CVE-2020-3467P3HIGHCVSS 7.7≤ 2.4v2.4\(0.357\)+8 more2020-10-08
CVE-2020-3467 [HIGH] CWE-863 CVE-2020-3467: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. The vulnerability is due to improper enforcement of role-based access control (RBAC) within the web-based management interface. An attacker could exploit th
nvd
CVE-2018-15459P3HIGHCVSS 7.2v2.3\(0.298\)v2.5\(0.1\)2019-01-23
CVE-2018-15459 [HIGH] CWE-284 CVE-2018-15459: A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could al A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on certain pages in the web interface. An attacker could exploit this vulnerability by authenticating to the device
nvd
CVE-2024-20531P3MEDIUMCVSS 6.5v3.0.0v3.1.0+3 more2024-11-06
CVE-2024-20531 [MEDIUM] CWE-611 CVE-2024-20531: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitr A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials. This vulnerab
nvd
CVE-2022-20966P3MEDIUMCVSS 5.4fixed in 2.6.0v2.6.0+4 more2023-01-20
CVE-2022-20966 [MEDIUM] CWE-79 CVE-2022-20966: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within th
nvd
CVE-2026-20148P3MEDIUMCVSS 4.9fixed in 3.1v3.1.0+40 more2026-04-15
CVE-2026-20148 [MEDIUM] CWE-22 CVE-2026-20148: A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perf A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An
nvd
CVE-2023-20077P3MEDIUMCVSS 6.5≤ 3.1v3.22023-05-18
CVE-2023-20077 [MEDIUM] CWE-37 CVE-2023-20077: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted H
nvd
CVE-2023-20087P3MEDIUMCVSS 6.5≤ 3.1v3.22023-05-18
CVE-2023-20087 [MEDIUM] CWE-37 CVE-2023-20087: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these vulnerabilities by sending crafted H
nvd
CVE-2019-1718P3HIGHCVSS 7.5v2.1\(0.907\)2019-04-17
CVE-2019-1718 [HIGH] CWE-399 CVE-2019-1718: A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthen A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of Secure Sockets Layer (SSL) renegotiation requests. An attacker could exploit this vulnerability by sendi
nvd
CVE-2016-6453P3HIGHCVSS 7.3v1.3\(0.876\)2016-11-03
CVE-2016-6453 [HIGH] CWE-89 CVE-2016-6453: A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an aut A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876).
nvd
CVE-2016-9198P3HIGHCVSS 7.5v1.2\(1.199\)2016-12-14
CVE-2016-9198 [HIGH] CWE-399 CVE-2016-9198: A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199).
nvd
CVE-2017-6653P3HIGHCVSS 7.5v2.1\(0.474\)2017-05-22
CVE-2017-6653 [HIGH] CWE-399 CVE-2017-6653: A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to respond to new or established connection requests. The vulnerability is due to insufficient TCP r
nvd
CVE-2023-20122P3HIGHCVSS 7.8v3.22023-04-05
CVE-2023-20122 [HIGH] CWE-77 CVE-2023-20122: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabilit
nvd
CVE-2019-1942P3MEDIUMCVSS 6.5≤ 2.6.02019-07-17
CVE-2019-1942 [MEDIUM] CWE-89 CVE-2019-1942: A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could a A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending c
nvd
CVE-2024-20537P3MEDIUMCVSS 6.5v3.0.0v3.1.0+2 more2024-11-06
CVE-2024-20537 [MEDIUM] CWE-863 CVE-2024-20537: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to a lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafte
nvd
CVE-2017-12261P3HIGHCVSS 7.8v1.4v2.0+2 more2017-11-02
CVE-2017-12261 [HIGH] CWE-264 CVE-2017-12261: A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessib A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the restricted shell. An attacker could
nvd
CVE-2021-40123P3MEDIUMCVSS 6.5≤ 2.6v2.6.0+7 more2021-10-21
CVE-2021-40123 [MEDIUM] CWE-266 CVE-2021-40123: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incorrect permissions settings on an affected device. An attacker could exploit this vulnerabilit
nvd
CVE-2023-20171P3MEDIUMCVSS 6.5v3.1v3.22023-05-18
CVE-2023-20171 [MEDIUM] CWE-602 CVE-2023-20171: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this
nvd
CVE-2026-20146P3MEDIUMCVSS 5.5fixed in 3.3.0v3.3.0+22 more2026-07-15
CVE-2026-20146 [MEDIUM] CWE-22 CVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (IS A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.
nvd
CVE-2024-20515P3MEDIUMCVSS 6.5v2.7.0v3.0.0+4 more2024-10-02
CVE-2024-20515 [MEDIUM] CWE-311 CVE-2024-20515: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to a lack of proper data protection mechanisms for certain configuration settings. An attacker with Read-Only Administrator priv
nvd