- EPSS 1.47%
- Veröffentlicht 16.07.2025 16:17:04
- Zuletzt bearbeitet 29.07.2025 01:00:01
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this...
CVE-2025-20285
- EPSS 0.04%
- Veröffentlicht 16.07.2025 16:16:56
- Zuletzt bearbeitet 22.07.2025 14:16:29
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability...
CVE-2025-20284
- EPSS 0.1%
- Veröffentlicht 16.07.2025 16:16:46
- Zuletzt bearbeitet 22.07.2025 14:19:49
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-suppl...
CVE-2025-20283
- EPSS 0.09%
- Veröffentlicht 16.07.2025 16:16:37
- Zuletzt bearbeitet 22.07.2025 14:19:31
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-suppl...
- EPSS 0.16%
- Veröffentlicht 25.06.2025 16:29:12
- Zuletzt bearbeitet 26.06.2025 20:35:33
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnera...
CVE-2025-20264
- EPSS 0.08%
- Veröffentlicht 25.06.2025 16:11:42
- Zuletzt bearbeitet 08.07.2025 14:53:22
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to ...
- EPSS 1.51%
- Veröffentlicht 25.06.2025 16:11:42
- Zuletzt bearbeitet 30.07.2025 19:24:26
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this...
CVE-2025-20130
- EPSS 0.07%
- Veröffentlicht 04.06.2025 16:17:27
- Zuletzt bearbeitet 22.07.2025 15:47:40
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerab...
CVE-2025-20267
- EPSS 0.06%
- Veröffentlicht 21.05.2025 16:20:15
- Zuletzt bearbeitet 22.07.2025 16:41:59
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to...
CVE-2025-20152
- EPSS 0.14%
- Veröffentlicht 21.05.2025 16:19:33
- Zuletzt bearbeitet 11.07.2025 15:22:26
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to impro...