Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +2 more
- <= 3.2
- <= 3.3
- <= 3.4
- <= 3.5
An authentication bypass vulnerability has been identified in the RADIUS Policy API endpoints of Cisco Identity Services Engine (ISE). This vulnerability allows an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive RADIUS Policy information on the affected device. The issue arises from improper role-based access control (RBAC) permissions, enabling attackers to bypass the web-based management interface and directly call the vulnerable API endpoints.
Exploitation of this vulnerability could lead to unauthorized read access to sensitive RADIUS Policy details that are normally restricted based on the user's role.
Users can upgrade to Cisco ISE version 3.3 Patch 11, 3.4 Patch 6, or 3.5 Patch 3. For versions 3.2 and earlier, migrating to a fixed release is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.