Vulnerabilità ed exploit · Attacco ad app web
Cisco ISE Richiede Verifica delle Patch Release per Release Le due vulnerabilità di Cisco ISE sono problemi separati, quindi correggere una build non significa che l’altra esposizione sia scomparsa. La consueta ipotesi una patch, un bug non vale in questo caso, soprattutto in ambienti che eseguono più release di ISE.
1 fonte · 6 mag
CVE-2026-20195 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
CVE-2026-20193 NVD KEV
CVSS 4.3 MEDIUM: a vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker…
Cronologia Fonti 6 mag Cisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device.
originale 5 mag Cisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-05-07
Every edition of this story: Cisco ISE Richiede Verifica delle Patch Release per Release
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
Cisco ISE Richiede Verifica delle Patch Release per Release Le due vulnerabilità di Cisco ISE sono problemi separati, quindi correggere una build non significa che l’altra esposizione sia scomparsa. La consueta ipotesi una patch, un bug non vale in questo caso, soprattutto in ambienti che eseguono più release di ISE.
1 fonte · 6 mag
CVE-2026-20195 NVD KEV
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
CVE-2026-20193 NVD KEV
CVSS 4.3 MEDIUM: a vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker…
Cronologia Fonti 6 mag Cisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device.
originale 5 mag Cisco PSIRT
Cisco Security Advisory: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
originale Riepilogo fornitore: Cisco
Part of the PlainSec briefing for 2026-05-07
Every edition of this story: Cisco ISE Richiede Verifica delle Patch Release per Release
Altro da oggi