cbcvebase.

Cisco Identity Services Engine vulnerabilities

166 known vulnerabilities affecting cisco/identity_services_engine.

Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2

Vulnerabilities

Page 7 of 9
CVE-2022-20959P4MEDIUMCVSS 5.4≥ 2.4, < 2.7.0v2.7.0+3 more2022-10-26
CVE-2022-20959 [MEDIUM] CWE-79 CVE-2022-20959: A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) S A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulne
nvd
CVE-2022-20963P4MEDIUMCVSS 5.4fixed in 2.7.0v2.7.0+2 more2022-11-04
CVE-2022-20963 [MEDIUM] CWE-87 CVE-2022-20963: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-bas
nvd
CVE-2024-20251P4MEDIUMCVSS 5.4v1.0v1.0.4+88 more2024-01-17
CVE-2024-20251 [MEDIUM] CWE-79 CVE-2024-20251: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-sup
nvd
CVE-2018-15456P4MEDIUMCVSS 4.9v2.2\(0.470\)v2.3\(0.298\)+2 more2019-01-10
CVE-2018-15456 [MEDIUM] CWE-200 CVE-2018-15456: A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authentic A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin Portal. An attacker with read or write access to the Admin Portal could e
nvd
CVE-2022-20914P4MEDIUMCVSS 4.9≥ 2.4.0, < 2.6.0v2.6.0+3 more2022-08-10
CVE-2022-20914 [MEDIUM] CWE-549 CVE-2022-20914: A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) S A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API output. An attacker could exploit this vulnerability by sending a crafted HTTP request to th
nvd
CVE-2019-12644P4MEDIUMCVSS 6.1fixed in 2.6.0v2.7\(0.207\)2019-09-05
CVE-2019-12644 [MEDIUM] CWE-79 CVE-2019-12644: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability exists because the web-based management interface of the aff
nvd
CVE-2018-15455P4MEDIUMCVSS 6.1v2.2\(0.910\)v2.3\(0.905\)+1 more2019-01-23
CVE-2018-15455 [MEDIUM] CWE-79 CVE-2018-15455: A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenti A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of requests stored in the system's logging database. An attacker could exploit this vulnerability by sending malicious requests to the t
nvd
CVE-2019-12631P4MEDIUMCVSS 6.1≤ 2.3v2.4+1 more2019-10-02
CVE-2019-12631 [MEDIUM] CWE-79 CVE-2019-12631: A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based managem
nvd
CVE-2021-34738P4MEDIUMCVSS 6.1fixed in 2.6.0v2.6.0+7 more2021-10-21
CVE-2021-34738 [MEDIUM] CWE-79 CVE-2021-34738: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-1673P4MEDIUMCVSS 5.4v2.5\(0.353\)2019-02-08
CVE-2019-1673 [MEDIUM] CWE-79 CVE-2019-1673: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management interface. An
nvd
CVE-2020-3157P4MEDIUMCVSS 5.4≤ 2.72020-03-04
CVE-2020-3157 [MEDIUM] CWE-79 CVE-2020-3157: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input to the web-based management interface. An attacker
nvd
CVE-2022-20967P4MEDIUMCVSS 5.4fixed in 2.6.0v2.6.0+4 more2023-01-20
CVE-2022-20967 [MEDIUM] CWE-79 CVE-2022-20967: A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within th
nvd
CVE-2024-20466P4MEDIUMCVSS 4.9≥ 2.7.0, < 3.1v3.1.0+2 more2024-08-21
CVE-2024-20466 [MEDIUM] CWE-266 CVE-2024-20466: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of administrative privilege levels for high-value sensitive data. An attacker with read-only Administrat
nvd
CVE-2019-1719P4MEDIUMCVSS 5.4v2.1\(0.474\)2019-04-18
CVE-2019-1719 [MEDIUM] CWE-79 CVE-2019-1719: A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based interface.
nvd
CVE-2017-6734P4MEDIUMCVSS 5.4v1.3\(0.722\)v1.3\(0.876\)+7 more2017-07-10
CVE-2017-6734 [MEDIUM] CWE-79 CVE-2017-6734: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, related to the Guest Portal. More Information: CSCvd74794. Known Affected Releases: 1.3(0.909) 2.1(
nvd
CVE-2019-12637P4MEDIUMCVSS 5.4≤ 2.3v2.3.0.298+1 more2019-10-16
CVE-2019-12637 [MEDIUM] CWE-79 CVE-2019-12637: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the
nvd
CVE-2019-12638P4MEDIUMCVSS 5.4≤ 2.2.0v2.3+5 more2019-10-16
CVE-2019-12638 [MEDIUM] CWE-79 CVE-2019-12638: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web-based management interface. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based man
nvd
CVE-2026-20193P4MEDIUMCVSS 4.3≤ 3.2.0v3.3.0+19 more2026-05-06
CVE-2026-20193 [MEDIUM] CWE-862 CVE-2026-20193: A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, r A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An at
nvd
CVE-2017-6605P4MEDIUMCVSS 5.4v2.1\(0.800\)2017-07-04
CVE-2017-6605 [MEDIUM] CWE-79 CVE-2017-6605: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc85415. Known Affected Releases: 2.1(0.800).
nvd
CVE-2020-3525P4MEDIUMCVSS 4.3v002.002\(000.916\)v002.003\(000.906\)+2 more2024-11-18
CVE-2020-3525 [MEDIUM] CWE-200 CVE-2020-3525: A vulnerability in the Admin portal of Cisco&nbsp;Identity Services Engine (ISE) could allow an auth A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved on an affected system. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin portal. An attacker with read or write
nvd