6.4

CVE-2025-20264

Medienbericht

Cisco Identity Services Engine Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.

This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series of specific commands to an affected device. A successful exploit could allow the attacker to modify a limited number of system settings, including some that would result in a system restart. In single-node Cisco ISE deployments, devices that are not authenticated to the network will not be able to authenticate until the Cisco ISE system comes back online. 
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Identity Services Engine Version 3.0.0 Update -
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.0.0 Update patch8
Cisco ≫ Identity Services Engine Version 3.1.0 Update -
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch10
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch8
Cisco ≫ Identity Services Engine Version 3.1.0 Update patch9
Cisco ≫ Identity Services Engine Version 3.2.0 Update -
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch5
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch6
Cisco ≫ Identity Services Engine Version 3.2.0 Update patch7
Cisco ≫ Identity Services Engine Version 3.3.0 Update -
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch1
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch2
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch3
Cisco ≫ Identity Services Engine Version 3.3.0 Update patch4
Cisco ≫ Identity Services Engine Version 3.4.0 Update -
Cisco ≫ Identity Services Engine Version 3.4.0 Update patch1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Cisco PSIRT 6.4 3.1 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-mVfKVQAU
Vendor Advisory