PT-2021-7256 · Cisco · Cisco Identity Services Engine

Published

2021-11-02

·

Updated

2023-07-24

·

CVE-2022-20733

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified)
Description A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This issue is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this by using the exposed SAML metadata to bypass authentication to the user portal, potentially accessing all roles without restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04305
CVE-2022-20733

Affected Products

Cisco Identity Services Engine