Cisco ISE是美国思科(Cisco)公司的一个 NAC 解决方案。用于管理零信任架构中的端点、用户和设备对网络资源的访问。 Cisco ISE存在安全漏洞,该漏洞源于RADIUS Policy API端点上基于角色的访问控制权限不当,可能导致具有只读管理员权限的经过身份验证的远程攻击者绕过Web管理界面直接调用受影响端点,获取未授权的敏感信息访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.3.0 |
affected |
3.3 Patch 2 |
affected | ||
3.3 Patch 1 |
affected | ||
3.3 Patch 3 |
affected | ||
3.4.0 |
affected | ||
3.3 Patch 4 |
affected | ||
3.4 Patch 1 |
affected | ||
3.3 Patch 5 |
affected | ||
| … +13 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20034 | 8.8 HIGH | Cisco Unity Connection Remote Code Execution Vulnerability |
| CVE-2026-20185 | 7.7 HIGH | Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vunerability |
| CVE-2026-20167 | 7.7 HIGH | Cisco IoT Field Network Director Remote Device Denial of Service Vulnerability |
| CVE-2026-20035 | 7.2 HIGH | Cisco Unity Connection Server-Side Request Forgery Vulnerability |
| CVE-2026-20168 | 6.5 MEDIUM | Cisco IoT Field Network Director Path Traversal Vulnerability |
| CVE-2026-20169 | 6.4 MEDIUM | Cisco IoT Field Network Director Command Injection Vulnerability |
| CVE-2026-20219 | 5.4 MEDIUM | Cisco Slido 安全漏洞 |
| CVE-2026-20195 | 5.3 MEDIUM | Cisco Identity Services Engine Observable Response Discrepancy Vulnerability |
| CVE-2026-20189 | 4.3 MEDIUM | Cisco Prime Infrastructure Information Disclosure Vulnerability |
| CVE-2026-20172 | 4.3 MEDIUM | Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability |
| CVE-2026-20188 | Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory |
No comments yet