Vulnerabilities > Cisco > Identity Services Engine

DATE CVE VULNERABILITY TITLE RISK
2019-04-18 CVE-2019-1719 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.1(0.474)
A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
5.4
2019-04-17 CVE-2019-1718 Unspecified vulnerability in Cisco Identity Services Engine 2.1(0.907)
A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2019-02-08 CVE-2019-1673 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.5(0.353)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
network
low complexity
cisco CWE-79
5.4
2019-01-23 CVE-2018-15459 Unspecified vulnerability in Cisco Identity Services Engine 2.3(0.298)/2.5(0.1)
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device.
network
low complexity
cisco
7.2
2019-01-23 CVE-2018-15455 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.2(0.910)/2.3(0.905)/2.4(0.903)
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
network
low complexity
cisco CWE-79
6.1
2019-01-23 CVE-2018-0187 Information Exposure vulnerability in Cisco Identity Services Engine 2.4(0.901.1)/2.4(0.901)
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts.
network
low complexity
cisco CWE-200
6.5
2019-01-10 CVE-2018-15456 Insufficiently Protected Credentials vulnerability in Cisco Identity Services Engine
A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text.
network
low complexity
cisco CWE-522
4.9
2018-10-05 CVE-2018-15425 Deserialization of Untrusted Data vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
network
low complexity
cisco CWE-502
4.7
2018-10-05 CVE-2018-15424 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Identity Services Engine 2.2(0.470)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
network
low complexity
cisco CWE-434
4.7
2018-05-17 CVE-2018-0277 Improper Certificate Validation vulnerability in Cisco Identity Services Engine
A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE application server to restart unexpectedly, causing a denial of service (DoS) condition on an affected system.
network
low complexity
cisco CWE-295
8.6