Identity Services Engine Software

Vendor:

First CVE: Sep 21, 2011 · Active for 14 years

49
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Identity Services Engine Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2011
14 years ago
Most Recent CVE
Oct 16, 2019
2,473 days ago

CVE Severity & Scoring

Identity Services Engine Software49 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (30.6%)
Unknown34 (69.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (30.6%)
High0 (0.0%)
Unknown34 (69.4%)
User Interaction
None6 (12.2%)
Unknown34 (69.4%)
Required9 (18.4%)
Privileges Required
Low2 (4.1%)
High1 (2.0%)
None12 (24.5%)
Unknown34 (69.4%)

Top CVEs

Signals from CVEs in this product scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or perform unspecified other adminis
Sep 21, 201110.029NONO
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forger
Aug 1, 20188.828NONO
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess
Nov 16, 20177.526NONO
The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to o
Jan 15, 20169.825NONO
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.
Jan 23, 20166.523NONO
The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 bef
Oct 25, 20139.023NONO
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripti
Jan 15, 20196.122NONO
A vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned by other users, because of SQL I
Feb 22, 20178.822NONO
Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user o
Dec 14, 20166.122NONO
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against
May 17, 20186.121NONO

Exploit Exposure

Signals from CVEs in this product scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (49 CVEs).

Media Mentions

Signals from CVEs in this product scope (49 CVEs).

Top CNAs Publishing CVEs For Identity Services Engine Software

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.4\(0.357\)45.20.9%00
2.4\(0.223\)16.11.8%00
2.4\(0.183\)18.81.2%00
2.4\(0.126\)16.11.8%00
2.3\(0.298\)26.11.8%00
2.2\(0.231\)18.81.2%00
2.1\(0.905\)16.11.8%00
2.1\(0.229\)17.52.0%00
2.1\(0.188\)18.81.2%00
2.0\(1.130\)16.11.8%00
2.0\(0.901\)18.81.2%00
2.0\(0.169\)16.81.0%00
2.0\(0.147\)16.81.0%00
1.4\(0.908\)18.81.8%00
1.4\(0.876\)16.81.0%00
1.4\(0.253\)28.22.2%00
1.4\(0.181\)37.71.8%00
1.4\(0.109\)28.22.2%00
1.415.52.1%00
1.3\(120.135\)36.91.9%00