QID 317200

Date Published: 2022-06-20

QID 317200: Cisco Identity Services Engine (ISE) Authentication Bypass Vulnerability (cisco-sa-ISE-SAML-nuukMPf9)

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restriction.

Affected versions:
From 3.1 Prior to 3.1 Patch2

A successful exploit could allow the attacker to access all roles without any restrictions.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ISE-SAML-nuukMPf9 for more information.

    CVEs related to QID 317200

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ISE-SAML-nuukMPf9 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-SAML-nuukMPf9