VDB

CVE-2022-20733

CVE-2022-20733 PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.

EPSS 1.10% · 63.3th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
1.10%
63.3th percentile

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Softwaren/a
ciscoidentity_services_engine3.1, 3.1

Timeline

  • Jun 15, 2022 CVE Published
  • Jun 16, 2022 EPSS Score
  • Aug 4, 2022 EPSS Score
  • Sep 21, 2022 EPSS Score
  • Nov 9, 2022 EPSS Score
  • Dec 27, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 21, 2023 EPSS Score
  • Jul 8, 2023 EPSS Score
  • Aug 25, 2023 EPSS Score
  • Oct 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›