Identity Services Engine Software
Vendor:
First CVE: Sep 21, 2011 · Active for 14 years
49
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Identity Services Engine Software over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2011
14 years ago
Most Recent CVE
Oct 16, 2019
2,473 days ago
CVE Severity & Scoring
Identity Services Engine Software49 CVEs
84%
12%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (30.6%)
Unknown34 (69.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (30.6%)
High0 (0.0%)
Unknown34 (69.4%)
User Interaction
None6 (12.2%)
Unknown34 (69.4%)
Required9 (18.4%)
Privileges Required
Low2 (4.1%)
High1 (2.0%)
None12 (24.5%)
Unknown34 (69.4%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3290HIGH Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other adminis | Sep 21, 2011 | 10.0 | 29 | NO | NO |
CVE-2018-0413HIGH A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forger | Aug 1, 2018 | 8.8 | 28 | NO | NO |
CVE-2017-12316HIGH A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess | Nov 16, 2017 | 7.5 | 26 | NO | NO |
CVE-2015-6323CRITICAL The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to o | Jan 15, 2016 | 9.8 | 25 | NO | NO |
CVE-2015-6317MEDIUM Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926. | Jan 23, 2016 | 6.5 | 23 | NO | NO |
CVE-2013-5530HIGH The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 bef | Oct 25, 2013 | 9.0 | 23 | NO | NO |
CVE-2018-15440MEDIUM A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripti | Jan 15, 2019 | 6.1 | 22 | NO | NO |
CVE-2017-3835HIGH A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL I | Feb 22, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-9214MEDIUM Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user o | Dec 14, 2016 | 6.1 | 22 | NO | NO |
CVE-2018-0327MEDIUM A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against | May 17, 2018 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Identity Services Engine Software
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.4\(0.357\) | 4 | 5.2 | 0.9% | 0 | 0 |
| 2.4\(0.223\) | 1 | 6.1 | 1.8% | 0 | 0 |
| 2.4\(0.183\) | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.4\(0.126\) | 1 | 6.1 | 1.8% | 0 | 0 |
| 2.3\(0.298\) | 2 | 6.1 | 1.8% | 0 | 0 |
| 2.2\(0.231\) | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.1\(0.905\) | 1 | 6.1 | 1.8% | 0 | 0 |
| 2.1\(0.229\) | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.1\(0.188\) | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.0\(1.130\) | 1 | 6.1 | 1.8% | 0 | 0 |
| 2.0\(0.901\) | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.0\(0.169\) | 1 | 6.8 | 1.0% | 0 | 0 |
| 2.0\(0.147\) | 1 | 6.8 | 1.0% | 0 | 0 |
| 1.4\(0.908\) | 1 | 8.8 | 1.8% | 0 | 0 |
| 1.4\(0.876\) | 1 | 6.8 | 1.0% | 0 | 0 |
| 1.4\(0.253\) | 2 | 8.2 | 2.2% | 0 | 0 |
| 1.4\(0.181\) | 3 | 7.7 | 1.8% | 0 | 0 |
| 1.4\(0.109\) | 2 | 8.2 | 2.2% | 0 | 0 |
| 1.4 | 1 | 5.5 | 2.1% | 0 | 0 |
| 1.3\(120.135\) | 3 | 6.9 | 1.9% | 0 | 0 |