Cisco ISE: Critical security vulnerability despite required admin rights

General News

Summary

Cisco has released security updates for Identity Services Engine, ISE Passive Identity Connector, Webex App, Umbrella Virtual Appliance, and Crosswork Network Controller. The most serious issue affects ISE and ISE-PIC and can lead to remote code execution and root compromise if an attacker already has admin rights. Cisco also fixed additional vulnerabilities that enable information disclosure, privilege escalation, open redirect attacks, and server-side template injection. Older ISE releases no longer receive patches, so affected customers must upgrade to a supported version. The incident creates immediate pressure for admins to review versions, apply updates, and validate exposure across Cisco environments.

Classifications

industries
No industries detected
applications
Business Intelligence

AskAI Classifications

Labels
SaaS Enterprise Software Collaboration Software

Linked Companies

Cisco
$1B+