CVE-2026-20190
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-285
Autorización incorrecta
Fecha de publicación:
17/06/2026
Última modificación:
22/06/2026
Descripción
*** Pendiente de traducción *** A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.<br />
<br />
This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.5.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch5:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



