CVE-2026-20195
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
Vulnerabilità · 147 giorni fa
Le due vulnerabilità di Cisco ISE sono problemi separati, quindi correggere una build non significa che l’altra esposizione sia scomparsa. La consueta ipotesi una patch, un bug non vale in questo caso, soprattutto in ambienti che eseguono più release di ISE.
CVSS 5.3 MEDIUM: a vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker…
CVSS 4.3 MEDIUM: a vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker…
1 fonte che coprono questa storia
Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device.
Cisco Security Advisory: Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
Part of the PlainSec briefing for 2026-05-07