Cisco Identity Services Engine Multiple Vulnerabilities (cisco-sa-ise-mult-vul-ymSsTLCc)

critical Nessus Plugin ID 348172

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco ISE is affected by multiple vulnerabilities.

- A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. (CVE-2026-20284)

- A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured. (CVE-2026-20284)

- A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. (CVE-2026-20282)

- A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.
Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
(CVE-2026-20282)

- A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system.
To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level.
(CVE-2026-20283)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwu31070, CSCwu40000, CSCwu66592

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu31070

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu40000

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu66592

http://www.nessus.org/u?4a04aedf

Plugin Details

Severity: Critical

ID: 348172

File Name: cisco-sa-ise-mult-vul-ymSsTLCc.nasl

Version: 1.1

Type: Local

Family: CISCO

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.8

Percentile: 99.34

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:N

CVSS Score Source: CVE-2026-20284

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software, cpe:/h:cisco:identity_services_engine

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-20282, CVE-2026-20283, CVE-2026-20284