CVE-2016-1402
- EPSS 1.99%
- Veröffentlicht 21.05.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a cra...
CVE-2015-6317
- EPSS 1.46%
- Veröffentlicht 23.01.2016 05:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
- EPSS 3.02%
- Veröffentlicht 15.01.2016 03:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw3...
- EPSS 2.06%
- Veröffentlicht 24.06.2015 10:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive inf...
CVE-2015-4182
- EPSS 2.09%
- Veröffentlicht 12.06.2015 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or change settings, via unspecified vectors, aka Bug ID CSC...
CVE-2014-8022
- EPSS 1.79%
- Veröffentlicht 15.01.2015 22:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and CSCur69776.
- EPSS 1.25%
- Veröffentlicht 22.12.2014 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted request that triggers inclusion of a password in a reply, aka Bug ID CSCur41673.
- EPSS 1.19%
- Veröffentlicht 22.12.2014 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Sponsor Portal in Cisco Identity Services Engine (ISE) allows remote authenticated users to obtain access to an arbitrary sponsor's guest account via a modified HTTP request, aka Bug ID CSCur64400.
CVE-2014-3275
- EPSS 1.56%
- Veröffentlicht 26.05.2014 00:25:31
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337.
- EPSS 2.19%
- Veröffentlicht 26.05.2014 00:25:31
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial o...