cbcvebase.

Cisco Identity Services Engine vulnerabilities

166 known vulnerabilities affecting cisco/identity_services_engine.

Total CVEs
166
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH37MEDIUM116LOW2

Vulnerabilities

Page 8 of 9
CVE-2024-20479P4MEDIUMCVSS 4.8v2.7.0v3.0.0+3 more2024-08-07
CVE-2024-20479 [MEDIUM] CWE-79 CVE-2024-20479: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerabilit
nvd
CVE-2024-20539P4MEDIUMCVSS 4.8v3.0.0v3.1.0+2 more2024-11-06
CVE-2024-20539 [MEDIUM] CWE-79 CVE-2024-20539: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit this vulnerability by injec
nvd
CVE-2026-20047P4MEDIUMCVSS 4.8fixed in 3.2v3.2.0+2 more2026-01-15
CVE-2026-20047 [MEDIUM] CWE-80 CVE-2026-20047: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Ci A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by th
nvd
CVE-2026-20076P4MEDIUMCVSS 4.8≤ 3.1.0v3.2+3 more2026-01-15
CVE-2026-20076 [MEDIUM] CWE-79 CVE-2026-20076: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affec
nvd
CVE-2020-3340P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6.02020-07-02
CVE-2020-3340 [MEDIUM] CWE-79 CVE-2020-3340: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input that is proce
nvd
CVE-2020-3149P4MEDIUMCVSS 4.8fixed in 2.72020-02-05
CVE-2020-3149 [MEDIUM] CWE-79 CVE-2020-3149: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack on an affected device. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this
nvd
CVE-2020-3589P4MEDIUMCVSS 4.8v2.2.0v2.2.0.470+7 more2020-10-08
CVE-2020-3589 [MEDIUM] CWE-79 CVE-2020-3589: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-based management interface does not properly validat
nvd
CVE-2021-34759P4MEDIUMCVSS 4.8fixed in 2.2.0v2.2.0+5 more2021-09-02
CVE-2021-34759 [MEDIUM] CWE-79 CVE-2021-34759: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly vali
nvd
CVE-2021-1606P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6\(0.999\)+4 more2021-07-08
CVE-2021-1606 [MEDIUM] CWE-79 CVE-2021-1606: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2021-1605P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6\(0.999\)+4 more2021-07-08
CVE-2021-1605 [MEDIUM] CWE-79 CVE-2021-1605: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2021-1604P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6\(0.999\)+4 more2021-07-08
CVE-2021-1604 [MEDIUM] CWE-79 CVE-2021-1604: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2021-1603P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6\(0.999\)+4 more2021-07-08
CVE-2021-1603 [MEDIUM] CWE-79 CVE-2021-1603: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2021-1607P4MEDIUMCVSS 4.8fixed in 2.6.0v2.6\(0.999\)+4 more2021-07-08
CVE-2021-1607 [MEDIUM] CWE-79 CVE-2021-1607: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user. These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker
nvd
CVE-2023-20208P4MEDIUMCVSS 4.8v3.0.0v3.1+1 more2023-11-21
CVE-2023-20208 [MEDIUM] CWE-87 CVE-2023-20208: A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, rem A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
nvd
CVE-2025-20204P4MEDIUMCVSS 4.8≥ 3.0.0, < 3.2v3.2.0+11 more2025-02-05
CVE-2025-20204 [MEDIUM] CWE-79 CVE-2025-20204: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management in
nvd
CVE-2025-20205P4MEDIUMCVSS 4.8≥ 3.0.0, < 3.2v3.2.0+11 more2025-02-05
CVE-2025-20205 [MEDIUM] CWE-79 CVE-2025-20205: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management in
nvd
CVE-2025-20267P4MEDIUMCVSS 4.8fixed in 3.2.0v3.2.0+2 more2025-05-21
CVE-2025-20267 [MEDIUM] CWE-80 CVE-2025-20267: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected syst
nvd
CVE-2026-20132P4MEDIUMCVSS 4.8fixed in 3.2.0v3.2.0+14 more2026-04-15
CVE-2026-20132 [MEDIUM] CWE-79 CVE-2026-20132: Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (IS Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device. These vul
nvd
CVE-2021-1416P4MEDIUMCVSS 4.3fixed in 2.3.0v2.3.0+4 more2021-02-17
CVE-2021-1416 [MEDIUM] CWE-266 CVE-2021-1416: Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. These vulnerabilities are due to improper enforcement of administrator privilege levels for sensitive data. An attacker with read-only administrator access to the Admin portal could exploit
nvd
CVE-2021-34702P4MEDIUMCVSS 4.3≥ 2.2.0, < 2.6.0v2.6.0+2 more2021-10-06
CVE-2021-34702 [MEDIUM] CWE-200 CVE-2021-34702: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to improper enforcement of administrator privilege levels for low-value sensitive data. An attacker with read-only administrator access to the web-based
nvd