VendorsCiscoidentity_services_engineall versions
Vulnerabilities

Cisco Identity Services Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

180CVEs
CVE-2023-20087
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
Published 2023-05-18 · Modified
6.5EPSS 0.008
CVE-2021-40123
Cisco Identity Services Engine File Download Vulnerability
Published 2021-10-21 · Modified
6.5EPSS 0.008
CVE-2023-20111
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface and viewing hidden fields within the application. A successful exploit could allow the attacker to access sensitive information, including device entry credentials, that could aid the attacker in further attacks.
Published 2023-08-16 · Modified
6.5EPSS 0.007
CVE-2024-20466
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2024-08-21 · Analyzed
6.5EPSS 0.005
CVE-2024-20537
Cisco Identity Services Engine Authorization Bypass Vulnerability
Published 2024-11-06 · Analyzed
6.5EPSS 0.005
CVE-2023-20171
Cisco Identity Services Engine Arbitrary File Delete and File Read Vulnerabilities
Published 2023-05-18 · Modified
6.5EPSS 0.004
CVE-2024-20531
Cisco Identity Services Engine XML External Entity Injection Vulnerability
Published 2024-11-06 · Analyzed
6.5EPSS 0.004
CVE-2024-20515
Cisco Identity Services Engine Information Disclosure Vulnerability
Published 2024-10-02 · Analyzed
6.5EPSS 0.003
CVE-2021-34706
Cisco Identity Services Engine XML External Entity Injection Vulnerability
Published 2021-10-06 · Modified
6.4EPSS 0.007
CVE-2025-20264
Cisco Identity Services Engine Authorization Bypass Vulnerability
Published 2025-06-25 · Analyzed
6.4EPSS 0.003
CVE-2018-0327
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvg86743.
Published 2018-05-17 · Modified
6.1EPSS 0.017
CVE-2018-0212
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf69963.
Published 2018-03-08 · Modified
6.1EPSS 0.017
CVE-2017-6701
A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd49141. Known Affected Releases: 2.1(102.101).
Published 2017-07-04 · Modified
6.1EPSS 0.013
CVE-2017-6733
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd87482. Known Affected Releases: 2.1(102.101) 2.2(0.283) 2.3(0.151).
Published 2017-07-10 · Modified
6.1EPSS 0.013
CVE-2019-1941
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2019-07-17 · Modified
6.1EPSS 0.013
CVE-2018-0091
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a Document Object Model (DOM) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf73922.
Published 2018-01-18 · Modified
6.1EPSS 0.012
CVE-2019-12644
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2019-09-05 · Modified
6.1EPSS 0.011
CVE-2018-15455
Cisco Identity Services Engine Logging Cross-Site Scripting Vulnerability
Published 2019-01-23 · Modified
6.1EPSS 0.011
CVE-2019-12631
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2019-10-02 · Modified
6.1EPSS 0.011
CVE-2020-3156
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2020-02-19 · Modified
6.1EPSS 0.011
CVE-2019-1719
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2019-04-18 · Modified
6.1EPSS 0.009
CVE-2020-3551
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2020-11-06 · Modified
6.1EPSS 0.008
CVE-2022-20959
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2022-10-26 · Modified
6.1EPSS 0.008
CVE-2023-20085
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script in the context of the affected interface or access sensitive, browser-based information.
Published 2023-02-16 · Modified
6.1EPSS 0.007
CVE-2021-34738
Cisco Identity Services Engine Cross-Site Scripting Vulnerabilities
Published 2021-10-21 · Modified
6.1EPSS 0.006
CVE-2021-40121
Cisco Identity Services Engine Cross-Site Scripting Vulnerabilities
Published 2021-10-21 · Modified
6.1EPSS 0.005
CVE-2024-20530
Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
6.1EPSS 0.003
CVE-2024-20525
Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
6.1EPSS 0.003
CVE-2024-20538
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
6.1EPSS 0.003
CVE-2013-5539
The upload-dialog implementation in Cisco Identity Services Engine (ISE) allows remote authenticated users to upload files with an arbitrary file type, and consequently conduct attacks against unspecified other systems, via a crafted file, aka Bug ID CSCui67511.
Published 2013-10-16 · Modified
6.0EPSS 0.010
CVE-2023-20030
Cisco Identity Services Engine XML External Entity Injection Vulnerability
Published 2023-04-05 · Modified
6.0EPSS 0.008
CVE-2026-20136
Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
Published 2026-04-15 · Analyzed
6.0EPSS 0.005
CVE-2023-20167
Cisco Identity Services Engine Path Traversal Vulnerabilities
Published 2023-05-18 · Modified
6.0EPSS 0.005
CVE-2020-3353
Cisco Identity Services Engine Denial of Service Vulnerability
Published 2020-06-03 · Modified
5.9EPSS 0.008
CVE-2018-0216
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. Cisco Bug IDs: CSCvf69805.
Published 2018-03-08 · Modified
5.8EPSS 0.008
CVE-2024-20527
Cisco Identity Services Engine Arbitrary File Read and Delete Vulnerability
Published 2024-11-06 · Analyzed
5.5EPSS 0.005
CVE-2024-20529
Cisco Identity Services Engine Arbitrary File Read and Delete Vulnerability
Published 2024-11-06 · Analyzed
5.5EPSS 0.005
CVE-2024-20532
Cisco Identity Services Engine Arbitrary File Read and Delete Vulnerability
Published 2024-11-06 · Analyzed
5.5EPSS 0.005
CVE-2026-20146
Cisco Identity Services Engine Path Traversal Vulnerability
Published 2026-07-15 · Analyzed
5.5EPSS 0.005
CVE-2024-20332
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To successfully exploit this vulnerability, the attacker would need valid Super Admin credentials.
Published 2024-04-03 · Analyzed
5.5EPSS 0.004
← Prev3 / 5Next →