Executive brief
Cisco Identity Services Engine (ISE) is a security policy management platform used to control network access and verify user identities. A vulnerability in this system allows an unauthorized person to remotely access sensitive internal data without needing a password. This could result in the exposure of encrypted user credentials, which attackers can use to gain further access to the corporate network.
Technical details
An information disclosure vulnerability exists in Cisco ISE and ISE-PIC due to improper authorization checks when specific resources are accessed. An unauthenticated, remote attacker can exploit this by sending crafted network traffic to the affected device. Successful exploitation allows the attacker to retrieve sensitive information, specifically including hashed credentials. The vulnerability is tracked under Cisco Bug ID CSCwt22936. Cisco has released software updates (3.4 Patch 6 and 3.5 Patch 3) to address the issue; no workarounds are available.
Affected products
- Cisco Identity Services Engine Software 3.4.0 through 3.4 Patch 5, 3.5.0 through 3.5 Patch 2
- Cisco ISE Passive Identity Connector 3.4.0
Timeline
- 2026-06-17: advisory: Initial public release by Cisco
- 2026-06-17: disclosed
- 2026-06-19: other: Advisory updated to clarify hot patch availability