Description
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Cisco / Cisco Identity Services Engine Software3.1.0 p8 – 3.1.0 p8
- Cisco / Cisco Identity Services Engine Software3.1.0 p9 – 3.1.0 p9
- Cisco / Cisco Identity Services Engine Software3.3 Patch 2 – 3.3 Patch 2
- Cisco / Cisco Identity Services Engine Software3.3 Patch 1 – 3.3 Patch 1
- Cisco / Cisco Identity Services Engine Software3.3 Patch 3 – 3.3 Patch 3
- Cisco / Cisco Identity Services Engine Software3.4.0 – 3.4.0
- Cisco / Cisco Identity Services Engine Software3.2.0 p7 – 3.2.0 p7
- Cisco / Cisco Identity Services Engine Software3.3 Patch 4 – 3.3 Patch 4
- Cisco / Cisco Identity Services Engine Software3.4 Patch 1 – 3.4 Patch 1
- Cisco / Cisco Identity Services Engine Software3.1.0 p10 – 3.1.0 p10
- Cisco / Cisco Identity Services Engine Software3.3 Patch 5 – 3.3 Patch 5
- Cisco / Cisco Identity Services Engine Software3.3 Patch 6 – 3.3 Patch 6
- Cisco / Cisco Identity Services Engine Software3.4 Patch 2 – 3.4 Patch 2
- Cisco / Cisco Identity Services Engine Software3.3 Patch 7 – 3.3 Patch 7
- Cisco / Cisco Identity Services Engine Software3.4 Patch 3 – 3.4 Patch 3
- Cisco / Cisco Identity Services Engine Software3.5.0 – 3.5.0
- Cisco / Cisco Identity Services Engine Software3.4 Patch 4 – 3.4 Patch 4
- Cisco / Cisco Identity Services Engine Software3.3 Patch 8 – 3.3 Patch 8
- Cisco / Cisco Identity Services Engine Software3.2 Patch 8 – 3.2 Patch 8
- Cisco / Cisco Identity Services Engine Software3.5 Patch 1 – 3.5 Patch 1
- Cisco / Cisco Identity Services Engine Software3.3 Patch 9 – 3.3 Patch 9
- Cisco / Cisco Identity Services Engine Software3.2 Patch 9 – 3.2 Patch 9
- Cisco / Cisco Identity Services Engine Software3.4 Patch 5 – 3.4 Patch 5
- Cisco / Cisco Identity Services Engine Software3.5 Patch 3 – 3.5 Patch 3
- Cisco / Cisco Identity Services Engine Software3.5 Patch 2 – 3.5 Patch 2
- Cisco / Cisco Identity Services Engine Software3.3 Patch 10 – 3.3 Patch 10
- Cisco / Cisco Identity Services Engine Software3.3 Patch 11 – 3.3 Patch 11
- Cisco / Cisco Identity Services Engine Software3.4 Patch 6 – 3.4 Patch 6
- Cisco / Cisco Identity Services Engine Software3.2 Patch 10 – 3.2 Patch 10
- Cisco / Cisco Identity Services Engine Software3.1.0 p11 – 3.1.0 p11
- Cisco / Cisco ISE Passive Identity Connector3.4.0 – 3.4.0
- Cisco / Cisco ISE Passive Identity Connector3.5.0 – 3.5.0
News coverage
- Cisco Zero-Day Highlights API Endpoint Authentication IssuesDark Reading · 2d ago
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksThe Hacker News · 4d ago
Updated 9m ago · 8 sources