Cisco 身份服务引擎(ISE)和 Cisco ISE 被动身份连接器(ISE-PIC)中存在一个漏洞,允许经过身份验证的远程攻击者对受影响的设备发起 SQL 或 HQL 注入攻击。 该漏洞是由于在将用户输入用于构建数据库查询之前,对受影响 API 中用户提供的输入验证不足所致。攻击者可以通过向受影响设备发送精心构造的请求来利用此漏洞。成功利用该漏洞后,攻击者可以针对底层数据库执行任意 SQL 或 HQL 查询,从而可能查看或修改其原本无权访问的数据。要利用此漏洞,攻击者必须拥有有效的管理员凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.1.0 |
affected |
3.1.0 p1 |
affected | ||
3.1.0 p3 |
affected | ||
3.1.0 p2 |
affected | ||
3.2.0 |
affected | ||
3.1.0 p4 |
affected | ||
3.1.0 p5 |
affected | ||
3.2.0 p1 |
affected | ||
| … +39 more rows | |||
| Cisco | Cisco ISE Passive Identity Connector | 3.2.0 |
affected |
3.1.0 |
affected | ||
3.3.0 |
affected | ||
3.4.0 |
affected | ||
3.5.0 |
affected | ||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.1.0 | - |
|
| Cisco | Cisco ISE Passive Identity Connector | 3.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20192 | 10.0 CRITICAL | Cisco Identity Services Engine Hardening Release - Access Control Vulnerabilities |
| CVE-2026-76460 | 10.0 CRITICAL | Cisco Identity Services Engine Authentication Bypass Vulnerability |
| CVE-2026-76423 | 10.0 CRITICAL | Cisco ISE API Authentication Bypass Vulnerability |
| CVE-2026-20130 | 10.0 CRITICAL | Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities |
| CVE-2026-20332 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20307 | 9.9 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20234 | 9.9 CRITICAL | Cisco Identity Services Engine Hardening Release - Insuffiencently Protected Credential Vu |
| CVE-2026-20324 | 9.9 CRITICAL | Cisco Secure Firewall Management Center sftunnel Root Arbitrary Code Exectution Vulnerabil |
| CVE-2026-20325 | 9.9 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutra |
| CVE-2026-20329 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20322 | 9.9 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Access |
| CVE-2026-20330 | 9.9 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20242 | 9.8 CRITICAL | Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Executio |
| CVE-2026-20326 | 9.8 CRITICAL | Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Missing Authent |
| CVE-2026-20331 | 9.6 CRITICAL | Cisco Secure Adaptive Security Appliance Software, Secure Firewall Threat Defense Software |
| CVE-2026-20306 | 9.1 CRITICAL | Cisco Identity Services Engine Command Injection Vulnerability |
| CVE-2026-20211 | 9.1 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20341 | 9.1 CRITICAL | Cisco Secure Firewall Management Center Software sftunnel Deserialization Root Command Exe |
| CVE-2026-20176 | 9.1 CRITICAL | Cisco Identity Services Engine Remote Code Execution Vulnerability |
| CVE-2026-20284 | 9.1 CRITICAL | Cisco Identity Search Engine SXP REST API SQL Injection Vulnerability |
Showing top 20 of 79 CVEs. View all on vendor page → →
No comments yet