Cisco Identity Services Engine vulnerabilities
166 known vulnerabilities affecting cisco/identity_services_engine.
Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2
Vulnerabilities
Page 4 of 9
CVE-2025-20264P3MEDIUMCVSS 6.4v3.0.0v3.1.0+3 more2025-06-25
CVE-2025-20264 [MEDIUM] CWE-285 CVE-2025-20264: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.
This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an exte
nvd
CVE-2019-15255P3MEDIUMCVSS 6.5v2.2v2.2\(0.470\)2020-01-26
CVE-2019-15255 [MEDIUM] CWE-284 CVE-2019-15255: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vuln
nvd
CVE-2025-20303P3MEDIUMCVSS 5.4≤ 3.1.0v3.2.0+2 more2025-11-05
CVE-2025-20303 [MEDIUM] CWE-79 CVE-2025-20303: Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could
Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An at
nvd
CVE-2023-20111P3MEDIUMCVSS 6.5≤ 2.6.0v2.7.0+2 more2023-08-16
CVE-2023-20111 [MEDIUM] CWE-497 CVE-2023-20111: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information.
This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit this vulnerability by logging in to
nvd
CVE-2026-20136P3MEDIUMCVSS 6.0fixed in 3.3.0v3.3.0+19 more2026-04-15
CVE-2026-20136 [MEDIUM] CWE-116 CVE-2026-20136: A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identi
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root.
This vulnerability is due to insufficient validatio
nvd
CVE-2019-1851P3MEDIUMCVSS 6.8v2.2\(0.470\)v2.3\(0.298\)+1 more2019-05-16
CVE-2019-1851 [MEDIUM] CWE-285 CVE-2019-1851: A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (IS
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE. This vulnerability is due to an incorrect implementation of role-based access control (RBAC). An attac
nvd
CVE-2018-0187P3MEDIUMCVSS 6.5v2.4\(0.901\)v2.4\(0.901.1\)2019-01-23
CVE-2018-0187 [MEDIUM] CWE-200 CVE-2018-0187: A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authentic
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts. The vulnerability is due to the improper handling of confidential information. An attacker could exploit this vulnerability by logging into the web interface on a vulnerab
nvd
CVE-2021-1412P3MEDIUMCVSS 6.5fixed in 2.3.0v2.3.0+4 more2021-02-17
CVE-2021-1412 [MEDIUM] CWE-266 CVE-2021-1412: Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an
Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit
nvd
CVE-2022-20782P3MEDIUMCVSS 6.5v2.6.0v2.7.0+2 more2022-04-06
CVE-2022-20782 [MEDIUM] CWE-266 CVE-2022-20782: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrato
nvd
CVE-2024-20469P3MEDIUMCVSS 6.7v3.2.0v3.3.02024-09-04
CVE-2024-20469 [MEDIUM] CWE-78 CVE-2024-20469: A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an auth
A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid Administrator privileges on an affected device.
This vulnerab
nvd
CVE-2022-20819P3MEDIUMCVSS 6.5fixed in 2.4.0.357≥ 2.6., < 2.6.0.156+3 more2022-06-15
CVE-2022-20819 [MEDIUM] CWE-266 CVE-2022-20819: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive data are not properly enforced. An attacker with read-only privileges for t
nvd
CVE-2024-20532P3MEDIUMCVSS 5.5≥ 3.0.0, < 3.1.0v3.1.0+2 more2024-11-06
CVE-2024-20532 [MEDIUM] CWE-22 CVE-2024-20532: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2024-20529P3MEDIUMCVSS 5.5≥ 3.0.0, < 3.1.0v3.1.0+2 more2024-11-06
CVE-2024-20529 [MEDIUM] CWE-22 CVE-2024-20529: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2024-20527P3MEDIUMCVSS 5.5≥ 3.0.0, < 3.1.0v3.1.0+2 more2024-11-06
CVE-2024-20527 [MEDIUM] CWE-22 CVE-2024-20527: A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and de
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could explo
nvd
CVE-2026-20195P3MEDIUMCVSS 5.3≤ 3.2.0v3.3.0+19 more2026-05-06
CVE-2026-20195 [MEDIUM] CWE-204 CVE-2026-20195: A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated,
A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device.
This vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted
nvd
CVE-2023-20021P3MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20021 [MEDIUM] CWE-78 CVE-2023-20021: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20022P3MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20022 [MEDIUM] CWE-78 CVE-2023-20022: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20023P3MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20023 [MEDIUM] CWE-78 CVE-2023-20023: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20152P3MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20152 [MEDIUM] CWE-77 CVE-2023-20152: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd
CVE-2023-20153P3MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20153 [MEDIUM] CWE-77 CVE-2023-20153: Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow a
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator privileges on the affected device. These
nvd