← Vulnerability feed

Vulnerability record · CVE-2015-6323 · published 15 January 2016

CVE-2015-6323: Cisco identity services engine software vulnerability

Cisco · Identity Services Engine Software

The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.

9.8 CVSS 3.0 Critical EPSS 3.0% · top 13.1%
9.8CVSS 3.0 base score, v2 10.0
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-6323 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3290Cisco identity services engine vulnerabilityCisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or pe…EPSS 2.3%9.0CVE-2013-5530Cisco identity services engine software os command injection vulnerabilityThe web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.…EPSS 2.3%8.8CVE-2018-0413Cisco identity services engine software cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…EPSS 1.2%8.8CVE-2017-3835Cisco identity services engine software sql injection vulnerabilityA vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned b…EPSS 1.8%7.5CVE-2017-12316Cisco identity services engine software improper authentication vulnerabilityA vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul…EPSS 2.0%7.5CVE-2016-1402Cisco identity services engine software memory buffer overflow vulnerabilityThe Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…EPSS 2.0%6.8CVE-2015-4267Cisco identity services engine software cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(…EPSS 1.00%6.8CVE-2013-5540Cisco identity services engine software vulnerabilityThe file-upload feature in Cisco Identity Services Engine (ISE) allows remote authenticated users to cause a denial of service (disk consumption and …EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2015-6323), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.