VendorsCiscoidentity_services_engineall versions
Vulnerabilities

Cisco Identity Services Engine

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

180CVEs
CVE-2021-1605
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Published 2021-07-08 · Modified
4.8EPSS 0.006
CVE-2021-1604
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Published 2021-07-08 · Modified
4.8EPSS 0.006
CVE-2021-1603
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Published 2021-07-08 · Modified
4.8EPSS 0.006
CVE-2023-20208
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
Published 2023-11-21 · Modified
4.8EPSS 0.005
CVE-2025-20204
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
Published 2025-02-05 · Modified
4.8EPSS 0.003
CVE-2025-20205
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
Published 2025-02-05 · Modified
4.8EPSS 0.003
CVE-2024-20479
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.
Published 2024-08-07 · Analyzed
4.8EPSS 0.003
CVE-2026-20047
Cisco Identity Services Engine Cross-Site Scripting Vulnerability
Published 2026-01-15 · Analyzed
4.8EPSS 0.003
CVE-2026-20076
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability
Published 2026-01-15 · Analyzed
4.8EPSS 0.003
CVE-2024-20539
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
4.8EPSS 0.003
CVE-2025-20267
Cisco Identity Services Stored Cross-Site Scripting Vulnerability
Published 2025-05-21 · Analyzed
4.8EPSS 0.003
CVE-2026-20132
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
Published 2026-04-15 · Analyzed
4.8EPSS 0.002
CVE-2021-1306
Cisco ADE-OS Local File Inclusion Vulnerability
Published 2021-05-22 · Modified
4.4EPSS 0.002
CVE-2014-0680
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.
Published 2014-01-29 · Modified
4.3EPSS 0.020
CVE-2021-34702
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2021-10-06 · Modified
4.3EPSS 0.009
CVE-2020-3525
Cisco Identity Services Engine Password Disclosure to an Unauthorized Actor Vulnerability
Published 2024-11-18 · Analyzed
4.3EPSS 0.006
CVE-2023-20213
A vulnerability in the CDP processing feature of Cisco ISE could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of the CDP process on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes CDP traffic. An attacker could exploit this vulnerability by sending crafted CDP traffic to the device. A successful exploit could cause the CDP process to crash, impacting neighbor discovery and the ability of Cisco ISE to determine the reachability of remote devices. After a crash, the CDP process must be manually restarted using the cdp enable command in interface configuration mode.
Published 2023-11-01 · Modified
4.3EPSS 0.003
CVE-2026-20193
Cisco Identity Services Engine Authentication Bypass Vulnerability
Published 2026-05-06 · Analyzed
4.3EPSS 0.002
CVE-2025-20285
Cisco Identity Services Engine IP Filter Access Restriction for Admin Access Configuration Bypass Vulnerability
Published 2025-07-16 · Analyzed
4.1EPSS 0.004
CVE-2013-5541
Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495.
Published 2013-10-16 · Modified
3.5EPSS 0.008
← Prev5 / 5