cbcvebase.

Cisco Identity Services Engine vulnerabilities

166 known vulnerabilities affecting cisco/identity_services_engine.

Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2

Vulnerabilities

Page 5 of 9
CVE-2023-20170P4MEDIUMCVSS 6.7v3.22023-11-01
CVE-2023-20170 [MEDIUM] CWE-77 CVE-2023-20170: A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to insuffici
nvd
CVE-2023-20166P4MEDIUMCVSS 6.7v3.22023-05-18
CVE-2023-20166 [MEDIUM] CWE-24 CVE-2023-20166: Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attack Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. For mo
nvd
CVE-2023-20193P4MEDIUMCVSS 6.7≤ 2.7≥ 3.0, ≤ 3.32023-09-07
CVE-2023-20193 [MEDIUM] CWE-78 CVE-2023-20193: A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, loca A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulner
nvd
CVE-2018-0215P4MEDIUMCVSS 6.3v2.0\(0.234\)2018-03-08
CVE-2018-0215 [MEDIUM] CWE-352 CVE-2018-0215: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an aff
nvd
CVE-2023-20030P3MEDIUMCVSS 6.0fixed in 3.2v3.22023-04-05
CVE-2023-20030 [MEDIUM] CWE-611 CVE-2023-20030: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based management interface itself. This vulnerab
nvd
CVE-2021-34706P4MEDIUMCVSS 5.4≤ 3.1v3.1\(0.518\)+1 more2021-10-06
CVE-2021-34706 [MEDIUM] CWE-611 CVE-2021-34706: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing
nvd
CVE-2018-0214P4MEDIUMCVSS 5.3v2.1\(102.103\)2018-03-08
CVE-2018-0214 [MEDIUM] CWE-20 CVE-2018-0214: A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authe A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input va
nvd
CVE-2024-20332P4MEDIUMCVSS 5.5v3.2.0v3.3.02024-04-03
CVE-2024-20332 [MEDIUM] CWE-918 CVE-2024-20332: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability b
nvd
CVE-2022-20965P4MEDIUMCVSS 5.4fixed in 2.6.0v2.6.0+4 more2023-01-20
CVE-2022-20965 [MEDIUM] CWE-648 CVE-2022-20965: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control on a feature within the web-based management interface of the affected system. An attacker coul
nvd
CVE-2018-0221P4MEDIUMCVSS 6.7v2.0\(0.249\)v2.1\(0.474\)+4 more2018-03-08
CVE-2018-0221 [MEDIUM] CWE-78 CVE-2018-0221: A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker needs valid administrator credentials for the device. The vulnerability is due to incomplete in
nvd
CVE-2020-27122P4MEDIUMCVSS 6.7fixed in 3.0.02020-11-06
CVE-2020-27122 [MEDIUM] CWE-266 CVE-2020-27122: A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE A vulnerability in the Microsoft Active Directory integration of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to elevate privileges on an affected device. To exploit this vulnerability, an attacker would need to have a valid administrator account on an affected device. The vulnerability is due to incorrect privil
nvd
CVE-2018-15425P4MEDIUMCVSS 4.7v2.1\(0.474\)v2.1\(0.907\)+6 more2018-10-05
CVE-2018-15425 [MEDIUM] CWE-20 CVE-2018-15425: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
nvd
CVE-2018-0275P4MEDIUMCVSS 6.7fixed in 2.2\(0.470\)2018-04-19
CVE-2018-0275 [MEDIUM] CWE-16 CVE-2018-0275: A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by tricking the device into unlocking the support user account and
nvd
CVE-2018-0212P4MEDIUMCVSS 6.1v2.1\(0.474\)v2.1\(0.904\)+2 more2018-03-08
CVE-2018-0212 [MEDIUM] CWE-79 CVE-2018-0212: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2023-20121P4MEDIUMCVSS 6.7v3.22023-04-05
CVE-2023-20121 [MEDIUM] CWE-77 CVE-2023-20121: Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more information about these vulnerabil
nvd
CVE-2024-20530P4MEDIUMCVSS 6.1v3.0.0v3.1.0+3 more2024-11-06
CVE-2024-20530 [MEDIUM] CWE-79 CVE-2024-20530: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, r A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2024-20525P4MEDIUMCVSS 6.1v3.0.0v3.1.0+3 more2024-11-06
CVE-2024-20525 [MEDIUM] CWE-79 CVE-2024-20525: A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, r A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a
nvd
CVE-2022-20937P4MEDIUMCVSS 5.3fixed in 2.7.0v2.7.0+2 more2022-11-04
CVE-2022-20937 [MEDIUM] CWE-410 CVE-2022-20937: A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) S A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit this vulnerability by taking action
nvd
CVE-2018-15424P4MEDIUMCVSS 4.7v2.2\(0.470\)2018-10-05
CVE-2018-15424 [MEDIUM] CWE-20 CVE-2018-15424: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
nvd
CVE-2023-20173P4MEDIUMCVSS 4.9fixed in 3.0.0v3.0.0+2 more2023-05-18
CVE-2023-20173 [MEDIUM] CWE-611 CVE-2023-20173: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the
nvd
Cisco Identity Services Engine vulnerabilities | cvebase