VendorsCiscoidentity_services_engineany version
Vulnerabilities

Cisco Identity Services Engine any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

99CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2011-3290
Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other administrative actions via unknown vectors, aka Bug ID CSCts59135.
Published 2011-09-21 · Modified
10.0EPSS 0.023
CVE-2025-20124
Cisco Identity Services Engine Java Deserialization Vulnerability
Published 2025-02-05 · Analyzed
9.91 PoCEPSS 0.185
CVE-2026-20147
Cisco Identity Services Engine Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.104
CVE-2026-20180
Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.060
CVE-2026-20186
Cisco Identity Services Engine Multiple Authenticated Remote Code Execution Vulnerability
Published 2026-04-15 · Analyzed
9.9EPSS 0.056
CVE-2021-1594
Cisco Identity Services Engine Privilege Escalation Vulnerability
Published 2021-10-06 · Modified
9.3EPSS 0.014
CVE-2025-20125
Cisco Identity Services Engine Insufficient Authorization Bypass Vulnerability
Published 2025-02-05 · Analyzed
9.11 PoCEPSS 0.164
CVE-2026-20181
Cisco Identity Services Engine Remote Code Execution Vulnerability
Published 2026-06-17 · Analyzed
9.1EPSS 0.089
CVE-2022-20964
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within requests as part of the web-based management interface. An attacker could exploit this vulnerability by manipulating requests to the web-based management interface to contain operating system commands. A successful exploit could allow the attacker to execute arbitrary operating system commands on the underlying operating system with the privileges of the web services user. Cisco has not yet released software updates that address this vulnerability.
Published 2023-01-18 · Modified
8.8EPSS 0.306
CVE-2022-20961
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the target user.
Published 2022-11-03 · Modified
8.8EPSS 0.004
CVE-2024-20368
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.
Published 2024-04-03 · Analyzed
8.8EPSS 0.003
CVE-2024-20486
Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
Published 2024-08-21 · Analyzed
8.8EPSS 0.003
CVE-2024-20417
Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabities
Published 2024-08-21 · Analyzed
8.1EPSS 0.005
CVE-2020-3467
Cisco Identity Services Engine Authorization Bypass Vulnerability
Published 2020-10-08 · Modified
7.7EPSS 0.009
CVE-2016-9198
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199).
Published 2016-12-14 · Modified
7.5EPSS 0.033
CVE-2016-1402
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted Password Authentication Protocol (PAP) authentication request, aka Bug ID CSCun25815.
Published 2016-05-21 · Modified
7.5EPSS 0.020
CVE-2025-20284
Cisco Identity Services Engine Authenticated Remote Code Execution Vulnerability
Published 2025-07-16 · Analyzed
7.2EPSS 0.174
CVE-2025-20283
Cisco Identity Services Engine Authenticated Remote Code Execution Vulnerability
Published 2025-07-16 · Analyzed
7.2EPSS 0.090
CVE-2023-20164
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-05-18 · Modified
7.2EPSS 0.011
CVE-2023-20163
Cisco Identity Services Engine Command Injection Vulnerabilities
Published 2023-05-18 · Modified
7.2EPSS 0.011
CVE-2024-20528
Cisco Identity Services Engine Path Traversal Vulnerability
Published 2024-11-06 · Analyzed
7.2EPSS 0.006
CVE-2025-20130
Cisco Identity Services Engine Access Control Bypass Vulnerability
Published 2025-06-04 · Analyzed
7.2EPSS 0.005
CVE-2024-20296
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit this vulnerability, an attacker would need at least valid Policy Admin credentials on the affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by uploading arbitrary files to an affected device. A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system, and elevate privileges to root.
Published 2024-07-17 · Analyzed
7.2EPSS 0.005
CVE-2018-0275
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell. The vulnerability is due to improper configuration of the support tunnel feature. An attacker could exploit this vulnerability by tricking the device into unlocking the support user account and accessing the tunnel password and device serial number. A successful exploit could allow the attacker to run any system command with root access. This affects Cisco Identity Services Engine (ISE) software versions prior to 2.2.0.470. Cisco Bug IDs: CSCvf54409.
Published 2018-04-19 · Modified
7.2EPSS 0.003
CVE-2020-27122
Cisco Identity Services Engine Privilege Escalation Vulnerability
Published 2020-11-06 · Modified
7.2EPSS 0.003
CVE-2013-5540
The file-upload feature in Cisco Identity Services Engine (ISE) allows remote authenticated users to cause a denial of service (disk consumption and administration-interface outage) by uploading many files, aka Bug ID CSCui67519.
Published 2013-10-16 · Modified
6.8EPSS 0.011
CVE-2013-3420
Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506.
Published 2013-07-17 · Modified
6.8EPSS 0.006
CVE-2023-20193
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ESR console. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges to root and read, write, or delete arbitrary files from the underlying operating system of the affected device. Note: The ESR is not enabled by default and must be licensed. To verify the status of the ESR in the Admin GUI, choose Administration > Settings > Protocols > IPSec.
Published 2023-09-07 · Analyzed
6.7EPSS 0.002
CVE-2019-1942
Cisco Identity Services Engine Blind SQL Injection Vulnerability
Published 2019-07-17 · Modified
6.5EPSS 0.012
CVE-2021-1412
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerabilities
Published 2021-02-17 · Modified
6.5EPSS 0.010
CVE-2022-20819
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2022-06-15 · Modified
6.5EPSS 0.010
CVE-2021-1416
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerabilities
Published 2021-02-17 · Modified
6.5EPSS 0.009
CVE-2023-20077
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
Published 2023-05-18 · Modified
6.5EPSS 0.008
CVE-2023-20087
Cisco Identity Services Engine Arbitrary File Download Vulnerabilities
Published 2023-05-18 · Modified
6.5EPSS 0.008
CVE-2021-40123
Cisco Identity Services Engine File Download Vulnerability
Published 2021-10-21 · Modified
6.5EPSS 0.008
CVE-2023-20111
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit this vulnerability by logging in to the web-based management interface and viewing hidden fields within the application. A successful exploit could allow the attacker to access sensitive information, including device entry credentials, that could aid the attacker in further attacks.
Published 2023-08-16 · Modified
6.5EPSS 0.007
CVE-2024-20466
Cisco Identity Services Engine Sensitive Information Disclosure Vulnerability
Published 2024-08-21 · Analyzed
6.5EPSS 0.005
CVE-2021-34706
Cisco Identity Services Engine XML External Entity Injection Vulnerability
Published 2021-10-06 · Modified
6.4EPSS 0.007
CVE-2018-0327
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Cisco Bug IDs: CSCvg86743.
Published 2018-05-17 · Modified
6.1EPSS 0.017
1 / 3Next →