VYPR

ISE

by Cisco Systems, Inc.

CVEs (76)

  • CVE-2025-20281CriKEVJun 25, 2025
    risk 0.85cvss 10.0epss 0.98

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2025-20337CriKEVJul 16, 2025
    risk 0.82cvss 10.0epss 0.68

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2026-76460CriKEVSep 16, 2026
    risk 0.78cvss 10.0epss 0.14

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by…

  • CVE-2025-20124CriFeb 5, 2025
    risk 0.69cvss 9.9epss 0.18

    A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An…

  • CVE-2025-20282CriJun 25, 2025
    risk 0.66cvss 10.0epss 0.39

    A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file…

  • CVE-2026-76423CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An…

  • CVE-2026-20147CriApr 15, 2026
    risk 0.65cvss 9.9epss 0.10

    A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This…

  • CVE-2026-20307CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged…

  • CVE-2025-20125CriFeb 5, 2025
    risk 0.63cvss 9.1epss 0.16

    A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and…

  • CVE-2026-20181CriJun 17, 2026
    risk 0.60cvss 9.1epss 0.09

    A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This…

  • CVE-2026-20284CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by…

  • CVE-2026-20211CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This…

  • CVE-2026-20176CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This…

  • CVE-2026-20306CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid…

  • CVE-2026-20305CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid…

  • CVE-2023-20175HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an attacker must have valid Read-only-level…

  • CVE-2017-12261HigNov 2, 2017
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to incomplete input validation of the user…

  • CVE-2026-76425HigSep 16, 2026
    risk 0.49cvss 7.6epss 0.00

    A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query.…

  • CVE-2026-20247HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted…

  • CVE-2026-20190HigJun 17, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability…

Page 1 of 4