CVE-2020-3467

HIGH

Cisco Identity Services Engine - Authenticated Incorrect Authorization via Web-Based Management Interface

Title source: llm
STIX 2.1

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. The vulnerability is due to improper enforcement of role-based access control (RBAC) within the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to modify parts of the configuration. The modified configuration could either allow unauthorized devices onto the network or prevent authorized devices from accessing the network. To exploit this vulnerability, an attacker would need valid Read-Only Administrator credentials.

References (1)

Core 1

Scores

CVSS v3 7.7
EPSS 0.0013
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (10)
cisco/identity_services_engine 2.4\(0.357\)
cisco/identity_services_engine 2.4.0.357 patch1 (12 CPE variants)
cisco/identity_services_engine 2.5
cisco/identity_services_engine 2.6\(0.156\)
cisco/identity_services_engine 2.6.0
cisco/identity_services_engine 2.6.0.156 patch1 (5 CPE variants)
cisco/identity_services_engine 2.7
cisco/identity_services_engine 2.7\(0.356\)
cisco/identity_services_engine 2.7.0.356 patch1
cisco/identity_services_engine < 2.4
Published Oct 08, 2020
Tracked Since Feb 18, 2026