VendorsCiscoidentity_services_engineall versions
Vulnerabilities

Cisco Identity Services Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

180CVEs
CVE-2016-6453
A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876).
Published 2016-11-03 · Modified
7.3EPSS 0.011
CVE-2025-20284
Cisco Identity Services Engine Authenticated Remote Code Execution Vulnerability
Published 2025-07-16 · Analyzed
7.2EPSS 0.174
CVE-2025-20283
Cisco Identity Services Engine Authenticated Remote Code Execution Vulnerability
Published 2025-07-16 · Analyzed
7.2EPSS 0.090
CVE-2018-15459
Cisco Identity Services Engine Privilege Escalation Vulnerability
Published 2019-01-23 · Modified
7.2EPSS 0.017
CVE-2023-20163
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-05-18 · Modified
7.2EPSS 0.011
CVE-2023-20164
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-05-18 · Modified
7.2EPSS 0.011
CVE-2018-0221
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker needs valid administrator credentials for the device. The vulnerability is due to incomplete input validation of user input for certain CLI ISE configuration commands. An attacker could exploit this vulnerability by authenticating as an administrative user, issuing a specific CLI command, and entering crafted, malicious user input for the command parameters. An exploit could allow the attacker to perform command injection to the lower-level Linux operating system. It is also possible the attacker could cause the ISE user interface for this management session to hang or disconnect. Cisco Bug IDs: CSCvg95479.
Published 2018-03-08 · Modified
7.2EPSS 0.008
CVE-2024-20528
Cisco Identity Services Engine Path Traversal Vulnerability
Published 2024-11-06 · Analyzed
7.2EPSS 0.006
CVE-2023-20196
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit these vulnerabilities by uploading a crafted file to an affected device. A successful exploit could allow the attacker to store malicious files in specific directories on the device. The attacker could later use those files to conduct additional attacks, including executing arbitrary code on the affected device with root privileges.
Published 2023-11-01 · Modified
7.2EPSS 0.006
CVE-2023-20195
Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit these vulnerabilities by uploading a crafted file to an affected device. A successful exploit could allow the attacker to store malicious files in specific directories on the device. The attacker could later use those files to conduct additional attacks, including executing arbitrary code on the affected device with root privileges.
Published 2023-11-01 · Modified
7.2EPSS 0.006
CVE-2025-20130
Cisco Identity Services Engine Access Control Bypass Vulnerability
Published 2025-06-04 · Analyzed
7.2EPSS 0.005
CVE-2024-20296
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by uploading arbitrary files to an affected device. A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system, and elevate privileges to root.
Published 2024-07-17 · Analyzed
7.2EPSS 0.005
CVE-2018-0275
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by tricking the device into unlocking the support user account and accessing the tunnel password and device serial number. A successful exploit could allow the attacker to run any system command with root access. This affects Cisco Identity Services Engine (ISE) software versions prior to 2.2.0.470. Cisco Bug IDs: CSCvf54409.
Published 2018-04-19 · Modified
7.2EPSS 0.003
CVE-2020-27122
Cisco Identity Services Engine Privilege Escalation Vulnerability
Published 2020-11-06 · Modified
7.2EPSS 0.003
CVE-2019-1736
Multiple Cisco UCS-Based Products UEFI Secure Boot Bypass Vulnerability
Published 2020-09-23 · Modified
6.9EPSS 0.002
CVE-2019-1851
Cisco Identity Services Engine Arbitrary Client Certificate Creation Vulnerability
Published 2019-05-16 · Modified
6.8EPSS 0.011
CVE-2013-5540
The file-upload feature in Cisco Identity Services Engine (ISE) allows remote authenticated users to cause a denial of service (disk consumption and administration-interface outage) by uploading many files, aka Bug ID CSCui67519.
Published 2013-10-16 · Modified
6.8EPSS 0.011
CVE-2018-0215
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections on the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCuv32863.
Published 2018-03-08 · Modified
6.8EPSS 0.008
CVE-2012-3908
Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hijack the authentication of administrators, aka Bug ID CSCty46684.
Published 2012-09-16 · Modified
6.8EPSS 0.006
CVE-2013-3420
Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506.
Published 2013-07-17 · Modified
6.8EPSS 0.006
CVE-2024-20469
Cisco Identity Services Engine Command Injection Vulnerability
Published 2024-09-04 · Analyzed
6.7EPSS 0.005
CVE-2023-20170
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted CLI command. A successful exploit could allow the attacker to elevate privileges to root.
Published 2023-11-01 · Modified
6.7EPSS 0.005
CVE-2023-20152
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.004
CVE-2023-20021
Cisco Identity Services Engine Privilege Escalation Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.004
CVE-2023-20153
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.004
CVE-2023-20022
Cisco Identity Services Engine Privilege Escalation Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.004
CVE-2023-20023
Cisco Identity Services Engine Privilege Escalation Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.004
CVE-2023-20166
Cisco Identity Services Engine Path Traversal Vulnerabilities
Published 2023-05-18 · Modified
6.7EPSS 0.002
CVE-2023-20121
Cisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection Vulnerabilities
Published 2023-04-05 · Modified
6.7EPSS 0.002
CVE-2023-20193
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ESR console. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges to root and read, write, or delete arbitrary files from the underlying operating system of the affected device. Note: The ESR is not enabled by default and must be licensed. To verify the status of the ESR in the Admin GUI, choose Administration > Settings > Protocols > IPSec.
Published 2023-09-07 · Analyzed
6.7EPSS 0.002
CVE-2018-15425
Multiple Vulnerabilities in Cisco Identity Services Engine
Published 2018-10-05 · Modified
6.5EPSS 0.016
CVE-2018-0187
Cisco Identity Services Engine Privileged Account Sensitive Information Disclosure Vulnerability
Published 2019-01-23 · Modified
6.5EPSS 0.015
CVE-2018-15424
Multiple Vulnerabilities in Cisco Identity Services Engine
Published 2018-10-05 · Modified
6.5EPSS 0.014
CVE-2019-1942
Cisco Identity Services Engine Blind SQL Injection Vulnerability
Published 2019-07-17 · Modified
6.5EPSS 0.012
CVE-2019-15255
Cisco Identity Services Engine Authorization Bypass Vulnerability
Published 2020-01-26 · Modified
6.5EPSS 0.011
CVE-2022-20782
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2022-04-06 · Modified
6.5EPSS 0.010
CVE-2021-1412
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerabilities
Published 2021-02-17 · Modified
6.5EPSS 0.010
CVE-2022-20819
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2022-06-15 · Modified
6.5EPSS 0.010
CVE-2021-1416
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerabilities
Published 2021-02-17 · Modified
6.5EPSS 0.009
CVE-2023-20077
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
Published 2023-05-18 · Modified
6.5EPSS 0.008
← Prev2 / 5Next →