Cisco Identity Services Engine vulnerabilities
155 known vulnerabilities affecting cisco/identity_services_engine.
Total CVEs
155
CISA KEV
3
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH36MEDIUM110LOW2
Vulnerabilities
Page 8 of 8
CVE-2018-0214MEDIUMCVSS 5.3v2.1\(102.103\)2018-03-08
CVE-2018-0214 [MEDIUM] CWE-20 CVE-2018-0214: A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authe
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection. These commands should have been restricted from this user. The vulnerability is due to insufficient input va
nvd
CVE-2018-0216MEDIUMCVSS 5.4v2.0\(0.249\)v2.1\(0.476\)+2 more2018-03-08
CVE-2018-0216 [MEDIUM] CWE-352 CVE-2018-0216: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an af
nvd
CVE-2018-0211MEDIUMCVSS 4.4v2.1\(0.474\)v2.2\(1.145\)+1 more2018-03-08
CVE-2018-0211 [MEDIUM] CWE-20 CVE-2018-0211: A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authe
A vulnerability in specific CLI commands for the Cisco Identity Services Engine could allow an authenticated, local attacker to cause a denial of service (DoS) condition. The device may need to be manually rebooted to recover. The vulnerability is due to lack of proper input validation of the CLI user input for certain CLI commands. An attacker could e
nvd
CVE-2018-0215MEDIUMCVSS 6.3v2.0\(0.234\)2018-03-08
CVE-2018-0215 [MEDIUM] CWE-352 CVE-2018-0215: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an aff
nvd
CVE-2018-0212MEDIUMCVSS 6.1v2.1\(0.474\)v2.1\(0.904\)+2 more2018-03-08
CVE-2018-0212 [MEDIUM] CWE-79 CVE-2018-0212: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2017-12261HIGHCVSS 7.8v1.4v2.0+2 more2017-11-02
CVE-2017-12261 [HIGH] CWE-264 CVE-2017-12261: A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessib
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the restricted shell. An attacker could
nvd
CVE-2017-6747CRITICALCVSS 9.8v1.3\(0.722\)v1.3\(0.876\)+16 more2017-08-07
CVE-2017-6747 [CRITICAL] CWE-287 CVE-2017-6747: A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenti
nvd
CVE-2017-6734MEDIUMCVSS 5.4v1.3\(0.722\)v1.3\(0.876\)+7 more2017-07-10
CVE-2017-6734 [MEDIUM] CWE-79 CVE-2017-6734: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, related to the Guest Portal. More Information: CSCvd74794. Known Affected Releases: 1.3(0.909) 2.1(
nvd
CVE-2017-6733MEDIUMCVSS 6.1v2.1\(102.101\)v2.2\(0.283\)+1 more2017-07-10
CVE-2017-6733 [MEDIUM] CWE-79 CVE-2017-6733: A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) p
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd87482. Known Affected Releases: 2.1(102.101) 2.2(0.283) 2.3(0.15
nvd
CVE-2017-6701MEDIUMCVSS 6.1v2.1\(102.101\)2017-07-04
CVE-2017-6701 [MEDIUM] CWE-79 CVE-2017-6701: A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal
A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd49141. Known Affected Releases: 2.1(102.101).
nvd
CVE-2017-6605MEDIUMCVSS 5.4v2.1\(0.800\)2017-07-04
CVE-2017-6605 [MEDIUM] CWE-79 CVE-2017-6605: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc85415. Known Affected Releases: 2.1(0.800).
nvd
CVE-2017-6653HIGHCVSS 7.5v2.1\(0.474\)2017-05-22
CVE-2017-6653 [HIGH] CWE-399 CVE-2017-6653: A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE
A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to respond to new or established connection requests. The vulnerability is due to insufficient TCP r
nvd
CVE-2016-9198HIGHCVSS 7.5v1.2\(1.199\)2016-12-14
CVE-2016-9198 [HIGH] CWE-399 CVE-2016-9198: A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199).
nvd
CVE-2016-6453HIGHCVSS 7.3v1.3\(0.876\)2016-11-03
CVE-2016-6453 [HIGH] CWE-89 CVE-2016-6453: A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an aut
A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876).
nvd
CVE-2012-3908MEDIUMCVSS 6.8v33002012-09-16
CVE-2012-3908 [MEDIUM] CWE-352 CVE-2012-3908: Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
nvd
← Previous8 / 8