VDB
CVE-2022-20733
CVE-2022-20733
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.
EPSS 1.10% · 63.3th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
1.10%
63.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Identity Services Engine Software | n/a |
| cisco | identity_services_engine | 3.1, 3.1 |
Timeline
- Jun 15, 2022 CVE Published
- Jun 16, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Sep 21, 2022 EPSS Score
- Nov 9, 2022 EPSS Score
- Dec 27, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 21, 2023 EPSS Score
- Jul 8, 2023 EPSS Score
- Aug 25, 2023 EPSS Score
- Oct 12, 2023 EPSS Score