cbcvebase.

Cisco Identity Services Engine Software vulnerabilities

32 known vulnerabilities affecting cisco/identity_services_engine_software.

Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM25

Vulnerabilities

Page 1 of 2
CVE-2017-3835P3HIGHCVSS 8.8v1.4\(0.908\)2017-02-22
CVE-2017-3835 [HIGH] CWE-89 CVE-2017-3835: A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authent A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL Injection. More Information: CSCvb15627. Known Affected Releases: 1.4(0.908).
nvd
CVE-2015-6323P3CRITICALCVSS 9.8v1.1.1v1.1.2+17 more2016-01-15
CVE-2015-6323 [CRITICAL] CVE-2015-6323: The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.
nvd
CVE-2013-5530P3CRITICALCVSS 9.0v1.0v1.1+5 more2013-10-25
CVE-2013-5530 [CRITICAL] CWE-78 CVE-2013-5530: The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 be The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443, aka Bug ID CSCuh81511.
nvd
CVE-2018-0413P3HIGHCVSS 8.8v2.0\(0.901\)v2.1\(0.188\)+2 more2018-08-01
CVE-2018-0413 [HIGH] CWE-352 CVE-2018-0413: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affe
nvd
CVE-2011-3290P3CRITICALCVSS 10.0≤ 1.0.4v1.0+1 more2011-09-21
CVE-2011-3290 [CRITICAL] CWE-255 CVE-2011-3290: Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.
nvd
CVE-2017-12316P3HIGHCVSS 7.5v2.1\(0.229\)2017-11-16
CVE-2017-12316 [HIGH] CWE-287 CVE-2017-12316: A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow a A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insufficient server-side login attempt limit enforcement. An attacker could exploit this vulnerability by
nvd
CVE-2016-1402P3HIGHCVSS 7.5v1.2.0.8992016-05-21
CVE-2016-1402 [HIGH] CWE-119 CVE-2016-1402: The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0. The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
nvd
CVE-2013-5525P3MEDIUMCVSS 6.5≤ 1.2v1.0+1 more2013-10-10
CVE-2013-5525 [MEDIUM] CWE-89 CVE-2013-5525: SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and ear SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
nvd
CVE-2014-3275P3MEDIUMCVSS 6.5≤ 1.2v1.0+1 more2014-05-26
CVE-2014-3275 [MEDIUM] CWE-89 CVE-2014-3275: SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patc SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337.
nvd
CVE-2015-6317P3MEDIUMCVSS 6.5v1.0.4.573v1.0_base+20 more2016-01-23
CVE-2015-6317 [MEDIUM] CWE-284 CVE-2015-6317: Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
nvd
CVE-2019-15282P4MEDIUMCVSS 5.3fixed in 2.4\(0.357\)v2.4\(0.357\)2019-10-16
CVE-2019-15282 [MEDIUM] CWE-306 CVE-2019-15282: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker read tcpdump files generated on an affected device. The vulnerability is due an issue in the authentication logic of the web-based management interface. An attacker could exploit this vulnerability by
nvd
CVE-2013-5531P4MEDIUMCVSS 5.0v1.0v1.12013-10-25
CVE-2013-5531 [MEDIUM] CWE-287 CVE-2013-5531: Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authenticati Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.
nvd
CVE-2015-4267P4MEDIUMCVSS 6.8v1.2\(0.793\)v1.3\(0.876\)+4 more2015-07-15
CVE-2015-4267 [MEDIUM] CWE-352 CVE-2015-4267: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engi Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), and 2.0(0.169) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus09940.
nvd
CVE-2018-0339P4MEDIUMCVSS 6.1v2.3\(0.298\)v2.4\(0.126\)2018-06-07
CVE-2018-0339 [MEDIUM] CWE-79 CVE-2018-0339: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management interface.
nvd
CVE-2018-0327P4MEDIUMCVSS 6.1v2.1\(0.905\)2018-05-17
CVE-2018-0327 [MEDIUM] CWE-79 CVE-2018-0327: A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthen A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software vi
nvd
CVE-2018-0289P4MEDIUMCVSS 6.1v2.3\(0.298\)v2.4\(0.223\)2018-05-17
CVE-2018-0289 [MEDIUM] CWE-79 CVE-2018-0289: A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticat A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application management interface. An attacker could exploit this vulnerability by sending malicious requests to
nvd
CVE-2012-3908P4MEDIUMCVSS 6.8v1.0v1.0.4+3 more2012-09-16
CVE-2012-3908 [MEDIUM] CWE-352 CVE-2012-3908: Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface ( Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
nvd
CVE-2016-9214P4MEDIUMCVSS 6.1v2.0\(1.130\)2016-12-14
CVE-2016-9214 [MEDIUM] CWE-79 CVE-2016-9214: Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, r Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvb86332 CSCvb86760. Known Affected Releases: 2.0(101.130).
nvd
CVE-2018-15463P4MEDIUMCVSS 6.1v2.4\(0.357\)2019-01-15
CVE-2018-15463 [MEDIUM] CWE-79 CVE-2018-15463: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient input validation of some parameters passed to the web-based management
nvd
CVE-2018-15440P4MEDIUMCVSS 6.1v2.4\(0.357\)2019-01-15
CVE-2018-15440 [MEDIUM] CWE-79 CVE-2018-15440: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient sanitization of user-supplied data that is written to log
nvd
Cisco Identity Services Engine Software vulnerabilities | cvebase