Cisco / Identity Services Engine Software
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-20469 | Cisco Identity Services Engine Command Injection Vulnerability | MEDIUM | 6.7 | Sep 4, 2024 |
| CVE-2024-20417 | Cisco Identity Services Engine REST API Blind SQL Injection Vulnerabities | HIGH | 8.1 | Aug 21, 2024 |
| CVE-2024-20296 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload arbitrary… | HIGH | 7.2 | Jul 17, 2024 |
| CVE-2019-15282 | Cisco Identity Services Engine Information Disclosure Vulnerability | MEDIUM | 5.3 | Oct 16, 2019 |
| CVE-2019-15281 | Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability | MEDIUM | 4.8 | Oct 16, 2019 |
| CVE-2018-15463 | Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities | MEDIUM | 6.1 | Jan 15, 2019 |
| CVE-2018-15440 | Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities | MEDIUM | 6.1 | Jan 15, 2019 |
| CVE-2018-0413 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cros… | HIGH | 8.8 | Aug 1, 2018 |
| CVE-2018-0339 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cros… | MEDIUM | 6.1 | Jun 7, 2018 |
| CVE-2018-0327 | A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting… | MEDIUM | 6.1 | May 17, 2018 |
| CVE-2018-0289 | A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks… | MEDIUM | 6.1 | May 17, 2018 |
| CVE-2017-12316 | A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple logi… | HIGH | 7.5 | Nov 16, 2017 |
| CVE-2017-3835 | A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other us… | HIGH | 8.8 | Feb 22, 2017 |
| CVE-2016-9214 | Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) atta… | MEDIUM | 6.1 | Dec 14, 2016 |
| CVE-2016-1485 | Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML via crafte… | MEDIUM | 6.1 | Aug 22, 2016 |
| CVE-2016-1402 | The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enab… | HIGH | 7.5 | May 21, 2016 |
| CVE-2015-6317 | Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka… | MEDIUM | 6.5 | Jan 23, 2016 |
| CVE-2015-6323 | The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows… | CRITICAL | 9.8 | Jan 15, 2016 |
| CVE-2015-6266 | The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to… | MEDIUM | 5.0 | Aug 28, 2015 |
| CVE-2015-4266 | The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which mak… | MEDIUM | 4.3 | Jul 16, 2015 |
| CVE-2015-4267 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(0.147), an… | MEDIUM | 6.8 | Jul 15, 2015 |
| CVE-2015-4268 | Multiple cross-site scripting (XSS) vulnerabilities in the Infra Admin UI in Cisco Identity Services Engine (ISE) 1.2(1.198) and 1.3(0.876) allow remote attack… | MEDIUM | 4.3 | Jul 14, 2015 |
| CVE-2015-4219 | Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access c… | MEDIUM | 4.0 | Jun 24, 2015 |
| CVE-2015-4182 | The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, a… | MEDIUM | 5.5 | Jun 12, 2015 |
| CVE-2015-0757 | The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote attackers… | MEDIUM | 5.0 | May 29, 2015 |
Showing 1 to 25 of 52 CVEs