Cisco Identity Services Engine Software vulnerabilities
32 known vulnerabilities affecting cisco/identity_services_engine_software.
Total CVEs
32
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM25
Vulnerabilities
Page 2 of 2
CVE-2015-4182P4MEDIUMCVSS 5.5v1.0.4.573v1.0_base+7 more2015-06-12
CVE-2015-4182 [MEDIUM] CWE-264 CVE-2015-4182: The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote au
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSCui72087.
nvd
CVE-2016-1485P4MEDIUMCVSS 6.1v1.3\(0.876\)2016-08-22
CVE-2016-1485 [MEDIUM] CWE-79 CVE-2016-1485: Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafted parameters, aka Bug ID CSCva46497.
nvd
CVE-2015-6266P4MEDIUMCVSS 5.0v1.2\(0.899\)2015-08-28
CVE-2015-6266 [MEDIUM] CWE-287 CVE-2015-6266: The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to
The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.
nvd
CVE-2015-0757P4MEDIUMCVSS 5.0v1.2\(1.901\)v1.3\(0.722\)2015-05-29
CVE-2015-0757 [MEDIUM] CWE-200 CVE-2015-0757: The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properl
The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers to obtain sensitive information by reading web pages, as demonstrated by MnT reports, aka Bug ID CSCuq23140.
nvd
CVE-2015-4219P4MEDIUMCVSS 4.0v1.0.4.5732015-06-24
CVE-2015-4219 [MEDIUM] CWE-200 CVE-2015-4219: Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Se
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug IDs CSCue00833 and CSCub40331.
nvd
CVE-2019-15281P4MEDIUMCVSS 4.8fixed in 2.4\(0.357\)v2.4\(0.357\)2019-10-16
CVE-2019-15281 [MEDIUM] CWE-79 CVE-2019-15281: A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Softwa
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The attacker must have valid administrator credentials. The vulnerability
nvd
CVE-2015-4268P4MEDIUMCVSS 4.3v1.2\(1.198\)v1.3\(0.876\)2015-07-14
CVE-2015-4268 [MEDIUM] CWE-79 CVE-2015-4268: Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services
Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCus16052.
nvd
CVE-2014-3276P4MEDIUMCVSS 4.0≤ 1.2v1.0+1 more2014-05-26
CVE-2014-3276 [MEDIUM] CWE-399 CVE-2014-3276: Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock c
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
nvd
CVE-2013-5524P4MEDIUMCVSS 4.3≤ 1.2v1.0+1 more2013-10-10
CVE-2013-5524 [MEDIUM] CWE-79 CVE-2013-5524: Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engi
Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655.
nvd
CVE-2014-0681P4MEDIUMCVSS 4.3≤ 1.22014-01-29
CVE-2014-0681 [MEDIUM] CWE-79 CVE-2014-0681: Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and ear
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.
nvd
CVE-2015-4266P4MEDIUMCVSS 4.3v1.1\(4.1\)v1.3\(106.146\)+1 more2015-07-16
CVE-2015-4266 [MEDIUM] CWE-20 CVE-2015-4266: The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) d
The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCut04556.
nvd
CVE-2013-5523P4MEDIUMCVSS 4.3≤ 1.2v1.0+1 more2013-10-10
CVE-2013-5523 [MEDIUM] CWE-20 CVE-2013-5523: The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restric
The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCui82666.
nvd
← Previous2 / 2