Vulnerabilities > Cisco > Identity Services Engine > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-05-16 CVE-2019-1851 Unspecified vulnerability in Cisco Identity Services Engine 2.2(0.470)/2.3(0.298)/2.4(0.357)
A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE.
network
low complexity
cisco
6.8
2019-04-18 CVE-2019-1719 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.1(0.474)
A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface.
network
low complexity
cisco CWE-79
5.4
2019-02-08 CVE-2019-1673 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.5(0.353)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface.
network
low complexity
cisco CWE-79
5.4
2019-01-23 CVE-2018-15455 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.2(0.910)/2.3(0.905)/2.4(0.903)
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
network
low complexity
cisco CWE-79
6.1
2019-01-23 CVE-2018-0187 Information Exposure vulnerability in Cisco Identity Services Engine 2.4(0.901.1)/2.4(0.901)
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts.
network
low complexity
cisco CWE-200
6.5
2019-01-10 CVE-2018-15456 Insufficiently Protected Credentials vulnerability in Cisco Identity Services Engine
A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text.
network
low complexity
cisco CWE-522
4.9
2018-10-05 CVE-2018-15425 Deserialization of Untrusted Data vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
network
low complexity
cisco CWE-502
4.7
2018-10-05 CVE-2018-15424 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco Identity Services Engine 2.2(0.470)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device with the privileges of the web server.
network
low complexity
cisco CWE-434
4.7
2018-04-19 CVE-2018-0275 Unspecified vulnerability in Cisco Identity Services Engine
A vulnerability in the support tunnel feature of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to access the device's shell.
local
low complexity
cisco
6.7
2018-03-08 CVE-2018-0221 OS Command Injection vulnerability in Cisco Identity Services Engine
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session.
local
low complexity
cisco CWE-78
6.7