VendorsCiscoidentity_services_engineall versions
Vulnerabilities

Cisco Identity Services Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

180CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2025-20281
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
10.0KEVEPSS 0.972
CVE-2025-20337
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
Published 2025-07-16 · Analyzed
10.0KEVEPSS 0.678
CVE-2025-20282
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
Published 2025-06-25 · Analyzed
10.0EPSS 0.293
CVE-2026-76460
Cisco Identity Services Engine Authentication Bypass Vulnerability
Published 2026-09-16 · Analyzed
10.0KEVEPSS 0.140
CVE-2011-3290
Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.
Published 2011-09-21 · Modified
10.0EPSS 0.023
CVE-2025-20124
Cisco Identity Services Engine Java Deserialization Vulnerability
Published 2025-02-05 · Analyzed
9.91 PoCEPSS 0.185
CVE-2026-20147
Cisco Identity Services Engine Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.104
CVE-2026-20180
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.060
CVE-2026-20186
Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.056
CVE-2025-20286
ISE on AWS Static Credential
Published 2025-06-04 · Analyzed
9.9EPSS 0.011
CVE-2017-6747
A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenticating with a valid external user account that matches an internal username and incorrectly receiving the authorization policy of the internal account. An exploit could allow the attacker to have Super Admin privileges for the ISE Admin portal. This vulnerability does not affect endpoints authenticating to the ISE. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance running Release 1.3, 1.4, 2.0.0, 2.0.1, or 2.1.0. Release 2.2.x is not affected. Cisco Bug IDs: CSCvb10995.
Published 2017-08-07 · Modified
9.8EPSS 0.055
CVE-2022-20733
Cisco Identity Services Engine Authentication Bypass Vulnerability
Published 2022-06-15 · Modified
9.8EPSS 0.011
CVE-2021-1594
Cisco Identity Services Engine Privilege Escalation Vulnerability
Published 2021-10-06 · Modified
9.3EPSS 0.014
CVE-2025-20125
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
Published 2025-02-05 · Analyzed
9.11 PoCEPSS 0.164
CVE-2026-20181
Cisco Identity Services Engine Remote Code Execution Vulnerability
Published 2026-06-17 · Analyzed
9.1EPSS 0.089
CVE-2022-20964
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management interface. An attacker could exploit this vulnerability by manipulating requests to the web-based management interface to contain operating system commands. A successful exploit could allow the attacker to execute arbitrary operating system commands on the underlying operating system with the privileges of the web services user. Cisco has not yet released software updates that address this vulnerability.
Published 2023-01-18 · Modified
8.8EPSS 0.306
CVE-2018-0213
A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP request. A successful exploit could allow the attacker to gain elevated privileges to access functionality that should be restricted. The attacker must have valid user credentials to the device to exploit this vulnerability. Cisco Bug IDs: CSCvf69753.
Published 2018-03-08 · Modified
8.8EPSS 0.025
CVE-2022-20956
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vulnerability. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx"]
Published 2022-11-03 · Modified
8.8EPSS 0.014
CVE-2022-20962
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges.
Published 2022-11-03 · Modified
8.8EPSS 0.010
CVE-2023-20272
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading a malicious file to the web interface. A successful exploit could allow the attacker to replace files and gain access to sensitive server-side information.
Published 2023-11-21 · Modified
8.8EPSS 0.009
CVE-2023-20175
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level privileges or higher on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.
Published 2023-11-01 · Modified
8.8EPSS 0.005
CVE-2022-20961
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the target user.
Published 2022-11-03 · Modified
8.8EPSS 0.004
CVE-2024-20368
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
Published 2024-04-03 · Analyzed
8.8EPSS 0.003
CVE-2024-20486
Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
Published 2024-08-21 · Analyzed
8.8EPSS 0.003
CVE-2018-0277
A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to incomplete input validation of the client EAP-TLS certificate. An attacker could exploit this vulnerability by initiating EAP authentication over TLS to the ISE with a crafted EAP-TLS certificate. A successful exploit could allow the attacker to restart the ISE application server, resulting in a DoS condition on the affected system. The ISE application could continue to restart while the client attempts to establish the EAP authentication connection. If an attacker attempted to import the same EAP-TLS certificate to the ISE trust store, it could trigger a DoS condition on the affected system. This exploit vector would require the attacker to have valid administrator credentials. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance. Cisco Bug IDs: CSCve31857.
Published 2018-05-17 · Modified
8.6EPSS 0.024
CVE-2022-20756
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability
Published 2022-04-06 · Modified
8.6EPSS 0.015
CVE-2023-20243
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could exploit this vulnerability by sending a crafted authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA). This would eventually result in the NAD sending a RADIUS accounting request packet to Cisco ISE. An attacker could also exploit this vulnerability by sending a crafted RADIUS accounting request packet to Cisco ISE directly if the RADIUS shared secret is known. A successful exploit could allow the attacker to cause the RADIUS process to unexpectedly restart, resulting in authentication or authorization timeouts and denying legitimate users access to the network or service. Clients already authenticated to the network would not be affected. Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) may be required. For more information, see the Details ["#details"] section of this advisory.
Published 2023-09-06 · Modified
8.6EPSS 0.009
CVE-2025-20152
ISE restart
Published 2025-05-21 · Analyzed
8.6EPSS 0.007
CVE-2025-20343
Cisco Identity Services Engine Radius Suppression Denial of Service Vulnerability
Published 2025-11-05 · Analyzed
8.6EPSS 0.007
CVE-2022-20822
Cisco Identity Services Engine Unauthorized File Access Vulnerability
Published 2022-10-26 · Modified
8.1EPSS 0.013
CVE-2024-20417
Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabities
Published 2024-08-21 · Analyzed
8.1EPSS 0.005
CVE-2019-1718
Cisco Identity Services Engine SSL Renegotiation Denial of Service Vulnerability
Published 2019-04-17 · Modified
7.8EPSS 0.025
CVE-2017-12261
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user input for CLI commands issued at the restricted shell. An attacker could exploit this vulnerability by authenticating to the targeted device and executing commands that could lead to elevated privileges. An attacker would need valid user credentials to the device to exploit this vulnerability. The vulnerability affects the following Cisco Identity Services Engine (ISE) products running Release 1.4, 2.0, 2.0.1, 2.1.0: ISE, ISE Express, ISE Virtual Appliance. Cisco Bug IDs: CSCve74916.
Published 2017-11-02 · Modified
7.8EPSS 0.003
CVE-2023-20122
Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
Published 2023-04-05 · Modified
7.8EPSS 0.002
CVE-2020-3467
Cisco Identity Services Engine Authorization Bypass Vulnerability
Published 2020-10-08 · Modified
7.7EPSS 0.009
CVE-2016-9198
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199).
Published 2016-12-14 · Modified
7.5EPSS 0.033
CVE-2017-6653
A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail to respond to new or established connection requests. The vulnerability is due to insufficient TCP rate limiting protection on the GUI. An attacker could exploit this vulnerability by sending the affected device a high rate of TCP connections to the GUI. An exploit could allow the attacker to cause the GUI to stop responding while the high rate of connections is in progress. Cisco Bug IDs: CSCvc81803.
Published 2017-05-22 · Modified
7.5EPSS 0.021
CVE-2016-1402
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Published 2016-05-21 · Modified
7.5EPSS 0.020
CVE-2026-20190
Cisco Identity Services Engine Information Disclosure Vulnerability
Published 2026-06-17 · Analyzed
7.5EPSS 0.005
1 / 5Next →