VendorsCiscoidentity_services_engine3.0.0
Vulnerabilities

Cisco Identity Services Engine 3.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2021-1606
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Published 2021-07-08 · Modified
4.8EPSS 0.006
CVE-2021-34759
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2021-09-02 · Modified
4.8EPSS 0.006
CVE-2023-20208
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
Published 2023-11-21 · Modified
4.8EPSS 0.005
CVE-2024-20479
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.
Published 2024-08-07 · Analyzed
4.8EPSS 0.003
CVE-2024-20539
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
4.8EPSS 0.003
CVE-2021-1306
Cisco ADE-OS Local File Inclusion Vulnerability
Published 2021-05-22 · Modified
4.4EPSS 0.002
CVE-2021-34702
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2021-10-06 · Modified
4.3EPSS 0.009
CVE-2023-20213
A vulnerability in the CDP processing feature of Cisco ISE could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of the CDP process on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes CDP traffic. An attacker could exploit this vulnerability by sending crafted CDP traffic to the device. A successful exploit could cause the CDP process to crash, impacting neighbor discovery and the ability of Cisco ISE to determine the reachability of remote devices. After a crash, the CDP process must be manually restarted using the cdp enable command in interface configuration mode.
Published 2023-11-01 · Modified
4.3EPSS 0.003
← Prev2 / 2